Security Policy Deployment via Network Topology and Device Capability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security measures at network perimeters are insufficient to effectively mitigate sophisticated malware threats, as they do not account for the varying capabilities of different devices within the network, leading to potential overworking of devices and performance degradation.

Innovation Solution

A security platform that receives network topology and device capability information to detect threats and selectively deploys security policies to appropriate enforcement devices based on threat information, optimizing the deployment to ensure network security without overburdening devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are deployed at network perimeters, then network security is provided, but sophisticated malware threats cannot be effectively mitigated and device capabilities are not considered leading to overworking of devices

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by deploying security policies selectively to specific enforcement devices based on their capabilities and locations within the network topology. Instead of uniformly applying security measures across all devices, the system identifies which devices have the capability to enforce particular security policies and assigns them accordingly. This ensures that security is enforced at the most appropriate locations in the network without overburdening devices that lack the necessary capabilities or are not optimally positioned to enforce the policies.

Inventive Principle:
Principle #3Local quality

2Reliability

If security policies are applied to all devices in the network, then comprehensive security coverage is achieved, but devices are overworked and performance degrades

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies segmentation by dividing the network into segments based on device capabilities and security policy requirements. The system identifies specific enforcement devices that are capable of handling particular security policies and assigns policies to those devices rather than distributing all policies to all devices. This segmentation approach ensures comprehensive security coverage while distributing the enforcement workload across only those devices that have the capability and are appropriately positioned, thereby preventing device overwork and performance degradation.

Inventive Principle:
Principle #1Segmentation

3Productivity

If security policies are selectively deployed based on device capability, then device performance is maintained, but complex analysis of network topology and device capabilities is required

Engineering Contradiction:
Improvedevice performanceVSAvoidpolicy deployment complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-characterizing device capabilities and storing capability information for each device in the network. Before security policies need to be deployed, the system has already gathered and stored information about which devices can enforce which types of security policies. When a security policy needs to be enforced, the system can quickly query this pre-stored capability information and the network topology to identify appropriate enforcement devices, rather than having to perform complex analysis at the time of policy deployment. This preliminary characterization significantly reduces the complexity of the policy deployment process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10771506B1Deployment of a security policy based on network topology and device capability
Publication Date: 2020.09.08 JUNIPER NETWORKS INC
  • US10771506B1 patent drawing
  • US10771506B1 patent drawing
  • US10771506B1 patent drawing

AI summary

A device may include one or more processors to receive network topology information of a network and device capability information of devices in the network; detect a threat to the network; determine threat information associated with the threat; select a security policy and an enforcement device of the network to enforce the security policy based on the network topology information, the device capability information, and the threat information; and perform an action associated with the threat based on the security policy and the enforcement device.