SDN Security Service Deployment Using Partial Malware Clones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security services are inefficient in detecting and mitigating evolving malware threats due to varying deployment strategies and operator-specific security priorities, necessitating a complex and time-consuming process to determine optimal deployment.

Innovation Solution

Deploying a set of security services on a software-defined network (SDN) and using partial clones of malware files to evaluate their performance across various aspects of malware behavior, allowing for automated deployment optimization based on weighted scoring and periodic updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security services are deployed to cover different malware types, then detection effectiveness is improved, but deployment complexity increases

Engineering Contradiction:
Improvedetection effectivenessVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically determines the optimal deployment configuration of security services by self-evaluating performance metrics against malware samples, eliminating the need for manual complex configuration and updating by security experts

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous monitoring and evaluation of security service performance, using feedback from detection results to automatically adjust and optimize the deployment configuration of security services

Inventive Principle:
Principle #23Feedback

2Reliability

If security deployment is manually optimized for each network, then detection effectiveness is improved, but time consumption increases

Engineering Contradiction:
Improvedetection effectivenessVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system creates virtual copies of malware samples and uses them in controlled evaluation environments to test security service performance, allowing parallel evaluation of multiple deployment configurations without time-consuming sequential manual optimization

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system pre-evaluates security service performance against a comprehensive set of malware samples and pre-determines optimal deployment configurations, so that when deployment is needed, the already-optimized configuration can be rapidly implemented

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security services are frequently updated to address evolving malware, then detection effectiveness is improved, but operational disruption increases

Engineering Contradiction:
Improvedetection effectivenessVSAvoidoperational disruption
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The system implements dynamic evaluation and adjustment of security service deployments, continuously adapting to evolving malware threats while maintaining operational continuity through automated updates that do not require manual intervention or cause service disruption

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4490641B1Computer-implemented network security method
Publication Date: 2026.03.11 BRITISH TELECOM PLC
  • EP4490641B1 patent drawingFigure 1
  • EP4490641B1 patent drawingFigure 2
  • EP4490641B1 patent drawingFigure 3

AI summary

A computer-implemented security method comprising: generating a plurality of partial clones of a malware file, each partial clone reflecting a different aspect of the malware file; causing trial deployment of one or more security services on a software-defined network (SDN); causing each of the plurality of partial clones to be run on a respective host; causing resulting traffic to be routed over the SDN, via one or more network elements on which the security services are deployed; causing performance of each of the security services with respect to each of the plurality of partial clones to be monitored to produce a respective plurality of security service performance measures for each of the security services; and causing operational deployment of a selected one or more of the security services on a network, in dependence on the one or more pluralities of security service performance measures.