Rule-Interpreting Module for Automated Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network rule-based security apparatuses require extensive manual knowledge and time from network administrators to establish and manage rules, especially with increasing network diversities and threats, making the process complex and time-consuming.

Innovation Solution

A rule-interpreting module that automatically detects suspicious traffic patterns, associates them with known threats, and generates applicable rules for the security apparatus, reducing the need for manual intervention and expertise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual rule establishment is used in rule-based security apparatus, then rule accuracy can be maintained, but the time and expertise required increases significantly

Engineering Contradiction:
Improverule accuracyVSAvoidtime for rule establishment
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-analysis by automatically capturing network packets, analyzing traffic flows, identifying suspicious patterns, and generating security rules without human intervention. The rule-based security apparatus serves itself by autonomously completing the entire rule establishment process from packet capture to rule deployment

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of rule creation by security experts is replaced with an automated electronic system that uses packet capture, traffic flow analysis, and pattern recognition algorithms to generate rules automatically, substituting human expertise with computational analysis

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual rule management is used, then security expertise can be applied, but the complexity and workload for administrators increases

Engineering Contradiction:
Improvesecurity protection qualityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically monitors network traffic, identifies threats, and updates security rules without requiring administrator intervention. The apparatus self-manages the complete security operation cycle including packet capture, analysis, rule generation, and deployment

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of network packets and traffic flows to identify suspicious patterns before threats materialize, proactively generating preventive security rules in advance rather than reacting to incidents

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If automated rule generation is implemented, then administrator workload is reduced, but the need for traffic flow analysis capability increases

Engineering Contradiction:
Improveadministrator workloadVSAvoidtraffic flow analysis capability
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The complex traffic flow analysis is broken down into discrete manageable steps: packet capture, association into flows, suspicious pattern identification, and rule generation. Each segment handles a specific aspect of the analysis process

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A packet capture module serves as an intermediary that collects raw network packets and transforms them into structured traffic flow data suitable for analysis, bridging the gap between raw network data and security rule requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10091167B2Network traffic analysis to enhance rule-based network security
Publication Date: 2018.10.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10091167B2 patent drawing
  • US10091167B2 patent drawing
  • US10091167B2 patent drawing

AI summary

A method of interpreting a rule and a rule-interpreting apparatus for rule-based security apparatus, and an apparatus implementing the method. The method comprises the following steps: designating a suspicious timeslot; if any packet does not present in the designated timeslot, capturing current incoming packets or capturing other incoming packets in the designated timeslot next time; automatically associating the packets in the designated timeslot to form at least one traffic flow corresponding to a connection or call; analyzing the at least one traffic flow to select at least one suspicious target traffic flow; and outputting the at least one selected suspicious target flow.