Security Device Policy Adjustment via Resource Utilization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security devices often face resource constraints, leading to reduced network availability or compromised security due to insufficient resources to perform multiple security services under heavy traffic loads.
Innovation Solution
A method and system where a security device identifies a resource profile based on resource utilization metrics and adjusts the security services profile to determine and perform a set of security services that align with available resources, thereby optimizing resource utilization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security services are enabled in a security policy, then network security is improved, but resource utilization increases leading to traffic drops or service bypassing under heavy traffic loads
Solution Approach 1:
The patent implements dynamic adjustment of security service profiles based on real-time resource utilization metrics. The security device monitors resource usage and automatically transitions between different security service profiles (e.g., from a first profile with comprehensive security services to a second profile with reduced services) when resource thresholds are exceeded, thereby adapting the system behavior dynamically to maintain network availability while preserving security as much as possible under constraints.
2Reliability
If multiple security services are performed simultaneously, then security coverage is improved, but device resource consumption increases beyond available capacity
Solution Approach 1:
The patent changes the operational parameters of security services by switching between different security service profiles that define different sets of security services. When resource utilization exceeds a threshold, the system transitions from a profile that enables multiple security services (IDP, UTM, AAMW, DPI, DNSF) to a profile that enables fewer services, thereby adjusting the quantity of security services performed to match available device resources.
Solution Approach 2:
The patent extracts or removes certain security services from the active configuration when resources are constrained. By transitioning to a second security service profile, the system selectively disables or bypasses non-essential security services while maintaining critical ones, thereby reducing resource consumption to match available capacity while preserving core security functionality.
3Reliability
If resource utilization is increased to maintain security services, then security performance is improved, but system stability deteriorates due to resource exhaustion
Solution Approach 1:
The patent implements a feedback mechanism where the security device continuously monitors resource utilization metrics and uses this information to adjust the security service profile. When resource utilization exceeds a predefined threshold, the system triggers a transition to a more resource-efficient security service profile, thereby preventing resource exhaustion and maintaining system stability. This closed-loop control ensures that security performance is optimized within the bounds of available resources.
Data Source
AI summary
In some implementations, a security device may identify a resource profile based on a value of a resource utilization metric associated with the security device. The security device may identify a security services profile to be applied to traffic that is to be processed by the security device. The security device may determine a set of security services to be performed by the security device, the set of security services being identified based on the resource profile and the security services profile. The security device may perform the set of security services according to the security services profile.


