Application Request Policy Assessment Using Sketch Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional container orchestration platforms are inefficient and fragmented in protecting against advanced threats, unable to scale properly, and struggle with the increased complexity of machine learning models and intense workloads due to rising data production from IoT devices and 5G networks.

Innovation Solution

Implementing a computer-implemented method that forwards application requests to a policy agent and a sketch algorithm, extracting metadata with probabilistic data structures to enforce security policies in real-time, reducing memory footprint by over 50% while maintaining accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional container orchestration platforms are used for security policy enforcement, then basic security measures are provided, but the platforms are fragmented and inefficient at protecting against advanced threats and unable to scale properly

Engineering Contradiction:
Improvesecurity policy enforcement effectivenessVSAvoidplatform fragmentation and inefficiency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security evaluation functions into a unified system that integrates policy agents, sketch algorithms, and machine learning models into a single coordinated architecture for security policy enforcement, eliminating the fragmented nature of conventional platforms

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security evaluation system is designed to handle multiple types of threats and workloads through a universal architecture that can process various application requests, metadata types, and security policies through a single multi-functional platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If more complex machine learning models are applied to evaluate security policies, then security assessment accuracy is improved, but the workload intensity and processing strain increase significantly

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidprocessing throughput under intense workload
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the security evaluation process into distinct components: sketch algorithms for rapid metadata extraction and initial filtering, policy agents for rule-based assessment, and machine learning models for complex threat detection. This segmentation allows each component to operate at optimal efficiency levels

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial action by using sketch algorithms to extract only the necessary metadata from application requests rather than analyzing complete request data, reducing the computational burden on machine learning models while maintaining assessment accuracy

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If complete application request data is processed for security policy evaluation, then thorough security assessment is achieved, but memory consumption and processing overhead increase

Engineering Contradiction:
Improvesecurity assessment thoroughnessVSAvoidmemory footprint
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential metadata from complete application requests using sketch algorithms, separating the necessary security evaluation data from the full request payload. This extraction reduces memory consumption while maintaining the thoroughness of security assessment through targeted analysis of critical fields

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250343821A1Accelerated policy assessment for requests
Publication Date: 2025.11.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20250343821A1 patent drawing
  • US20250343821A1 patent drawing
  • US20250343821A1 patent drawing

AI summary

A computer-implemented method, according to one approach, is performed in response to intercepting an application request. The computer-implemented method includes forwarding a first copy of the application request to a policy agent, and forwarding a second copy of the application request to a sketch algorithm. The sketch algorithm extracts metadata from the second copy of the application request. Moreover, the policy agent applies a security policy to the first copy of the application request and the metadata extracted by the sketch algorithm. Furthermore, the application request is dispositioned based at least in part on whether the first copy of the application request and/or the metadata extracted by the sketch algorithm satisfy the security policy.