Security Policy Deployment via Network Topology and Device Capability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security measures at network perimeters are insufficient to effectively mitigate sophisticated malware threats, as they do not account for the varying capabilities of different devices within the network, leading to potential overworking of devices and performance degradation.
Innovation Solution
A security platform that receives network topology and device capability information to detect threats and selectively deploys security policies to appropriate enforcement devices based on threat information, optimizing the deployment to ensure network security without overburdening devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security measures are deployed at network perimeters, then network security is provided, but sophisticated malware threats cannot be effectively mitigated and device capabilities are not considered leading to overworking of devices
Solution Approach 1:
The patent applies local quality by deploying security policies selectively to specific enforcement devices based on their capabilities and locations within the network topology. Instead of uniformly applying security measures across all devices, the system identifies which devices have the capability to enforce particular security policies and assigns them accordingly. This ensures that security is enforced at the most appropriate locations in the network without overburdening devices that lack the necessary capabilities or are not optimally positioned to enforce the policies.
2Reliability
If security policies are applied to all devices in the network, then comprehensive security coverage is achieved, but devices are overworked and performance degrades
Solution Approach 1:
The patent applies segmentation by dividing the network into segments based on device capabilities and security policy requirements. The system identifies specific enforcement devices that are capable of handling particular security policies and assigns policies to those devices rather than distributing all policies to all devices. This segmentation approach ensures comprehensive security coverage while distributing the enforcement workload across only those devices that have the capability and are appropriately positioned, thereby preventing device overwork and performance degradation.
3Productivity
If security policies are selectively deployed based on device capability, then device performance is maintained, but complex analysis of network topology and device capabilities is required
Solution Approach 1:
The patent applies preliminary action by pre-characterizing device capabilities and storing capability information for each device in the network. Before security policies need to be deployed, the system has already gathered and stored information about which devices can enforce which types of security policies. When a security policy needs to be enforced, the system can quickly query this pre-stored capability information and the network topology to identify appropriate enforcement devices, rather than having to perform complex analysis at the time of policy deployment. This preliminary characterization significantly reduces the complexity of the policy deployment process.
Data Source
AI summary
A device may include one or more processors to receive network topology information of a network and device capability information of devices in the network; detect a threat to the network; determine threat information associated with the threat; select a security policy and an enforcement device of the network to enforce the security policy based on the network topology information, the device capability information, and the threat information; and perform an action associated with the threat based on the security policy and the enforcement device.


