Device-Specific Security Rule Compilation for Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks face challenges in effectively securing against distributed denial-of-service (DDoS) attacks and botnet attacks due to the need for customized security rules that account for varying network device configurations and capabilities.

Innovation Solution

An apparatus and method that generate device-specific security rules for network devices by compiling security rules based on network device information, including configuration and telemetry data, to create rules tailored to the device's capabilities and resources, thereby enhancing security against DDoS and botnet attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If generic security rules are applied to all network devices, then deployment simplicity is improved, but security effectiveness deteriorates due to varying device configurations and capabilities

Engineering Contradiction:
Improvedeployment simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adjusts security rule parameters based on network device capabilities, resource availability, and threat characteristics. The compilation process transforms generic security rules into device-specific implementations by modifying parameters such as rule priority, matching criteria, and enforcement mechanisms to match each device's configuration and capabilities.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The security rule compilation process segments the generic security rule into multiple device-specific rules tailored to individual network devices. Each device receives a customized subset of security rules that account for its specific capabilities, resources, and role in the network, rather than applying a monolithic set of rules to all devices.

Inventive Principle:
Principle #1Segmentation

2Reliability

If customized security rules are generated for each network device, then security effectiveness is improved, but system complexity worsens due to individualized configuration requirements

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network device autonomously participates in the security rule compilation process by providing its capability information and configuration parameters to the controller. The device self-configures by receiving and applying compiled security rules that are automatically tailored to its specific characteristics, eliminating the need for manual individual configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The controller acts as an intermediary that manages the complexity of generating customized security rules. It receives generic security rules, compiles them into device-specific rules based on device capabilities and network policies, and distributes them to appropriate devices. This centralised compilation process abstracts the complexity from individual devices while maintaining customisation benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive security rules are deployed across all devices, then security coverage is improved, but resource consumption worsens due to processing overhead on network devices

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The compilation process implements partial action by selecting and applying only the necessary subset of security rules for each network device based on its capabilities and role. Rather than deploying comprehensive security rules to all devices, the system applies only those rules that are relevant and enforceable on each specific device, reducing processing overhead while maintaining adequate security coverage.

Inventive Principle:
Principle #16Partial or excessive action

4Productivity

If security rules are optimized for specific device capabilities, then rule execution efficiency is improved, but adaptability worsens when device configurations vary

Engineering Contradiction:
Improverule execution efficiencyVSAvoidconfiguration adaptability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The security rule compilation system is dynamic and adaptive, automatically adjusting the compilation process based on current device capabilities, network conditions, and security requirements. When device configurations vary or change, the controller re-evaluates and recompiles security rules to match the updated device characteristics, maintaining both optimisation and adaptability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250047714A1Programming security rules into network devices
Publication Date: 2025.02.06 NOKIA SOLUTIONS & NETWORKS OY
  • US20250047714A1 patent drawing
  • US20250047714A1 patent drawing
  • US20250047714A1 patent drawing

AI summary

Various example embodiments for supporting network security for a communication network are presented herein. Various example embodiments for supporting network security for a communication network may be configured to support programming of security functions, including security rules, into network devices. Various example embodiments for supporting programming of security functions into network devices may be configured to support programming of security functions into high performance application-specific integrated circuits (ASICs) of the network device. Various example embodiments for supporting programming of security functions into network devices may be configured to support programming of security functions into various types of network device, such as routers, switches, servers, or the like.