Security Indication Spanning Tree for Network Attack Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional intrusion protection systems are inadequate in preventing the spread of attacks within centralized networks, as they focus on external breaches and lack efficient methods to identify and prioritize internal vulnerabilities, leading to potential widespread damage from initial attacks on seemingly insignificant components.

Innovation Solution

A security indication spanning tree system that determines asset value and exposure ratings of network nodes, analyzing the risk of attack spread and creating a spanning tree schematic to prioritize security threats and facilitate effective resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion protection systems are deployed to protect individual network components, then initial breach prevention is improved, but internal attack spread detection and response capability deteriorates

Engineering Contradiction:
Improveinitial breach preventionVSAvoidinternal attack spread detection
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into a spanning tree structure with hierarchical levels, dividing the complex network security problem into manageable segments. Each node is assigned a security indication based on its position and characteristics in the spanning tree, allowing localized security management while maintaining overall network security awareness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension for security assessment by creating a spanning tree representation that adds hierarchical and topological dimensions to traditional flat network security models. This dimensional transformation enables visualization and analysis of attack spread pathways that were previously difficult to detect.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If centralized resources are consolidated to reduce costs and improve efficiency, then resource utilization is improved, but vulnerability to internal attack spread increases

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidinternal attack spread vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary actions by pre-calculating and assigning security indications to each node in the spanning tree before attacks occur. Exposure ratings and asset values are determined in advance, enabling rapid response to attacks by immediately identifying high-risk nodes and potential attack pathways without requiring complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms by continuously monitoring network traffic and updating security indications based on detected threats. The system provides feedback about attack patterns and node vulnerabilities, allowing dynamic adjustment of security resources and response strategies to protect centralized assets from internal attack spread.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive security monitoring is implemented across the entire network, then attack detection capability is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different security indication levels to different nodes based on their specific characteristics, positions in the spanning tree, and asset values. Rather than uniform monitoring, each node receives appropriate security attention based on its local importance and vulnerability, reducing overall system complexity while maintaining detection precision for critical nodes.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8042187B2Security indication spanning tree system and method
Publication Date: 2011.10.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8042187B2 patent drawing
  • US8042187B2 patent drawing
  • US8042187B2 patent drawing

AI summary

A security indication spanning tree system and method is presented. In one embodiment the asset value of a network node is determined. The exposure rating of said network node is ascertained. The impact risk to a preferred functionality due to an attack from another network node is analyzed. A spanning tree schematic of a network including the network node is created, wherein the spanning tree schematic includes an indication of the asset value.