Security Appliance Identifies Entities via Virtual Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a computing environment, identifying and associating security entities becomes challenging as the number of security entities and transactions increases, making it difficult to maintain network integrity.

Innovation Solution

A security appliance monitors communication between user computers and destination computers, extracts selective information, assigns virtual identifiers, and identifies security entities based on this information, associating them with corresponding entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication monitoring and security entity identification is conducted in an enterprise computing environment, then network integrity is maintained, but the complexity of identifying and tracking numerous security entities increases significantly

Engineering Contradiction:
Improvenetwork integrityVSAvoidsecurity entity identification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security appliance as an intermediary device that sits between network traffic sources and destinations. This appliance automatically performs security entity identification, communication monitoring, and relationship mapping, thereby maintaining network integrity without requiring enterprise personnel to manually manage the complex identification and tracking of numerous security entities across the computing environment

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the number of security entities and transactions in the computing environment increases, then more comprehensive security coverage is achieved, but selective identification of security entities becomes increasingly challenging

Engineering Contradiction:
Improvesecurity coverageVSAvoidselective identification difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The security appliance performs self-service by automatically extracting selective information from communications, identifying security entities, and mapping their relationships without human intervention. The system autonomously handles the challenging task of selective identification even as the number of security entities and transactions increases, maintaining comprehensive security coverage while eliminating manual identification efforts

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes of security entity identification and tracking with automated electronic systems. The security appliance uses electronic information extraction, virtual identifier assignment, and automated relationship mapping to substitute human analysts, thereby making selective identification feasible even in environments with large numbers of security entities and transactions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11108796B1System and method for identifying security entities in a computing environment
Publication Date: 2021.08.31 ARISTA NETWORKS INC
  • US11108796B1 patent drawing
  • US11108796B1 patent drawing
  • US11108796B1 patent drawing

AI summary

System and method to identify a security entity in a computing environment is disclosed. Communication between a user computer and at least one destination computer by a security appliance is monitored by a security appliance. A virtual identifier is assigned to a subset of the communication within a defined time period. At least one security entity is identified based on a subset of the selective information. The assigned virtual identifier associated with at least one security entity.