Security Microservices Passive Policy Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in determining the optimal duration for monitoring network traffic, leading to inefficient security deployments due to either insufficient or delayed responses, and are affected by changes in computing environments such as audits or backups, making it difficult to obtain a representative understanding of normal traffic patterns.
Innovation Solution
Implementing security microservices that passively apply security policies to live network traffic to evaluate and recommend modifications to resource groups and security policies, allowing for active enforcement without impacting traffic, thereby optimizing security configurations and improving threat detection and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security policies are actively enforced on network traffic, then threat detection capability is improved, but network performance and traffic flow are degraded
Solution Approach 1:
The system performs preliminary sampling of network traffic to establish baseline patterns before actively enforcing security policies. This preliminary action allows the system to prepare detection rules and thresholds in advance, enabling threat detection without real-time performance degradation.
Solution Approach 2:
The patent introduces an intermediary sampling mechanism that creates a representative subset of traffic for analysis. This intermediary layer allows security policies to be evaluated on sampled traffic without applying them to all network flow, thus maintaining detection capability while preserving overall network performance.
2Measurement precision
If network traffic is monitored for an extended period to obtain representative patterns, then understanding of normal traffic is improved, but response time to security threats is delayed
Solution Approach 1:
The system applies partial monitoring by sampling a representative subset of network traffic rather than analyzing all traffic in full. This partial action provides sufficient information to establish normal patterns quickly, enabling faster response times while maintaining adequate measurement precision through strategic sampling.
Solution Approach 2:
The system performs preliminary sampling during off-peak periods or in advance to establish baseline traffic patterns before threats occur. This preliminary understanding of normal behavior enables faster anomaly detection when threats arise, reducing response time while maintaining pattern accuracy.
3Adaptability or versatility
If security configurations are modified based on changing computing environments, then adaptability to new threats is improved, but system stability is degraded
Solution Approach 1:
The system continuously monitors sampled network traffic and provides feedback on detected patterns and anomalies. This feedback mechanism enables adaptive adjustment of security configurations based on actual traffic observations while maintaining stability through controlled, incremental modifications rather than abrupt changes.
Solution Approach 2:
The patent implements dynamic security configurations that can adapt to changing computing environments through sampled traffic analysis. The system balances adaptability by allowing configurations to evolve based on observed patterns while maintaining core stability through baseline comparisons and controlled adjustment mechanisms.
Data Source
AI summary
Systems, methods, and apparatuses enable one or more security microservices to optimize a security configuration of a networked environment by applying security policies to resource groups passively to determine whether network sets, resource groups, or security policies should be modified, prior to active enforcement. When security policies are applied passively, security actions that are performed in response to a violation of security policy do not impact network traffic. The one or more security microservices evaluate the results of the passive application of security policies to determine whether there is at least one recommended modification to network sets, resource groups, or security policies. When there is at least one recommended modification, the modification is applied. When there are no recommended modifications or the recommended modifications have been performed, the one or more security microservices initiate active enforcement of at least a subset of the security policies on the network traffic.


