Automated Server Clustering for Network Security Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in configuring optimal Denial of Service (DoS) countermeasures for servers due to the complexity of understanding individual server services and the tedious process of grouping servers for customized security settings, which requires intimate knowledge and is time-consuming, especially as networks evolve.

Innovation Solution

A method and system that analyze network traffic samples to determine suggested security filter settings for each server, cluster servers based on similarity, and apply common security filter settings to each cluster, using machine learning techniques like the K-means algorithm and linear regression for efficient DDoS/DoS countermeasures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network administrators manually configure customized security filter settings for each server, then security protection effectiveness is improved, but the configuration process becomes time-consuming and operationally complex

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically analyzing network traffic samples, determining service types, generating suggested security filter settings, and clustering servers without requiring manual administrator intervention for each server, thus maintaining security effectiveness while eliminating time-consuming manual configuration

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameter of security configuration from manual static settings to dynamically generated settings based on analyzed network traffic patterns and service types, enabling automated adaptation to different server configurations while maintaining protection effectiveness

Inventive Principle:
Principle #35Parameter changes

2Reliability

If network administrators manually group servers and configure protection settings, then customized security countermeasures are achieved, but the process requires intimate knowledge of each server and becomes tedious

Engineering Contradiction:
Improvecustomized security countermeasuresVSAvoidconfiguration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically performs server analysis, service type determination, and clustering without requiring administrator knowledge of individual server configurations. The system serves itself by generating all necessary security configurations based on automated traffic analysis

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system segments the complex task of security configuration into automated sub-tasks: capturing network traffic samples, analyzing traffic patterns, determining service types, generating suggested settings, and clustering servers. This segmentation eliminates the need for administrators to understand each server individually

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive understanding of each server service is obtained, then optimal security filter settings are determined, but the complexity of the configuration process increases

Engineering Contradiction:
Improvesecurity settings accuracyVSAvoidconfiguration process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically obtains comprehensive understanding of each server by analyzing network traffic samples and determining service types without requiring administrator intervention. This self-service approach maintains measurement precision while eliminating configuration complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces the manual mechanical process of understanding and configuring each server with an automated electronic analysis system that captures and analyzes network traffic samples, determining service types and generating security settings automatically, thus maintaining accuracy while reducing complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Adaptability or versatility

If security configuration is repeated as networks evolve, then updated protection is achieved, but ongoing time and operational resources are consumed

Engineering Contradiction:
Improvenetwork evolution adaptationVSAvoidconfiguration efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system implements dynamic security configuration that automatically adapts as networks evolve. By continuously analyzing network traffic samples and re-clustering servers based on current service types, the system maintains updated protection without requiring repeated manual configuration efforts

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-updates by automatically detecting network changes through traffic analysis, re-determining service types, and re-generating security configurations without requiring administrator intervention, thus maintaining adaptability while preserving productivity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11343228B2Automatically configuring clustered network services
Publication Date: 2022.05.24 ARBOR NETWORKS INC
  • US11343228B2 patent drawing
  • US11343228B2 patent drawing
  • US11343228B2 patent drawing

AI summary

A computer method and system for determining common network security filter settings for one or more clusters of network servers. Network traffic samples are captured which are associated with a plurality of network servers. The captured network traffic samples are collated with regards to each of the plurality of network servers. The collated network traffic is analyzed for each of the plurality of network servers for determining suggested network security filter settings for each network server. One or more clusters of network servers are determined contingent upon the determined suggested network security filter settings for each of the plurality of network servers. Common network security group filter settings are determined for each determined cluster of network servers.