Security Microservices Passive Policy Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in determining the optimal duration for monitoring network traffic, leading to inefficient security deployments due to either insufficient or delayed responses, and are affected by changes in computing environments such as audits or backups, making it difficult to obtain a representative understanding of normal traffic patterns.

Innovation Solution

Implementing security microservices that passively apply security policies to live network traffic to evaluate and recommend modifications to resource groups and security policies, allowing for active enforcement without impacting traffic, thereby optimizing security configurations and improving threat detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are actively enforced on network traffic, then threat detection capability is improved, but network performance and traffic flow are degraded

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary sampling of network traffic to establish baseline patterns before actively enforcing security policies. This preliminary action allows the system to prepare detection rules and thresholds in advance, enabling threat detection without real-time performance degradation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary sampling mechanism that creates a representative subset of traffic for analysis. This intermediary layer allows security policies to be evaluated on sampled traffic without applying them to all network flow, thus maintaining detection capability while preserving overall network performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If network traffic is monitored for an extended period to obtain representative patterns, then understanding of normal traffic is improved, but response time to security threats is delayed

Engineering Contradiction:
Improveunderstanding of normal traffic patternsVSAvoidresponse time to threats
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial monitoring by sampling a representative subset of network traffic rather than analyzing all traffic in full. This partial action provides sufficient information to establish normal patterns quickly, enabling faster response times while maintaining adequate measurement precision through strategic sampling.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary sampling during off-peak periods or in advance to establish baseline traffic patterns before threats occur. This preliminary understanding of normal behavior enables faster anomaly detection when threats arise, reducing response time while maintaining pattern accuracy.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If security configurations are modified based on changing computing environments, then adaptability to new threats is improved, but system stability is degraded

Engineering Contradiction:
Improveadaptability to new threatsVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system continuously monitors sampled network traffic and provides feedback on detected patterns and anomalies. This feedback mechanism enables adaptive adjustment of security configurations based on actual traffic observations while maintaining stability through controlled, incremental modifications rather than abrupt changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements dynamic security configurations that can adapt to changing computing environments through sampled traffic analysis. The system balances adaptability by allowing configurations to evolve based on observed patterns while maintaining core stability through baseline comparisons and controlled adjustment mechanisms.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11368488B2Optimizing a security configuration of a networked environment
Publication Date: 2022.06.21 FORTINET INC
  • US11368488B2 patent drawing
  • US11368488B2 patent drawing
  • US11368488B2 patent drawing

AI summary

Systems, methods, and apparatuses enable one or more security microservices to optimize a security configuration of a networked environment by applying security policies to resource groups passively to determine whether network sets, resource groups, or security policies should be modified, prior to active enforcement. When security policies are applied passively, security actions that are performed in response to a violation of security policy do not impact network traffic. The one or more security microservices evaluate the results of the passive application of security policies to determine whether there is at least one recommended modification to network sets, resource groups, or security policies. When there is at least one recommended modification, the modification is applied. When there are no recommended modifications or the recommended modifications have been performed, the one or more security microservices initiate active enforcement of at least a subset of the security policies on the network traffic.