Threat Intelligence Policy Automation for Network Security Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security management is overwhelmed by the need to manually configure security devices and policies in response to ever-changing threats, with thousands of rules and lack of access to all security devices across networks, leading to inefficiency and resource consumption.

Innovation Solution

A system that generates a security infrastructure profile using threat intelligence data to automatically configure network security devices and policies, including firewall rules and other security measures, based on risk scores and thresholds, without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of security devices and policies is performed to address new threats, then security protection capability is improved, but management time and resources are consumed excessively

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidmanagement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security management system automatically discovers security devices, collects configuration information, and updates security policies without requiring manual intervention. The system self-configures by parsing device configurations, identifying security parameters, and pushing updated policies to relevant devices, thereby eliminating time-consuming manual configuration processes while maintaining security protection capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A centralized security management system acts as an intermediary between threat intelligence sources and distributed security devices. This mediator automatically processes threat information, generates appropriate security policies, and distributes them to firewalls and other security devices across the network, replacing manual configuration efforts with automated intermediary-driven policy management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security coverage across all networks is achieved, then security protection capability is improved, but system complexity increases due to lack of access to all security devices

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security management system implements a universal configuration approach that can discover and manage multiple types of security devices (firewalls, intrusion prevention systems, etc.) across different networks through standardized protocols and interfaces. This multi-functional capability enables comprehensive security coverage without requiring separate manual configuration processes for each device type or network, thereby reducing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The centralized security management system serves as a universal intermediary that abstracts the complexity of accessing and configuring diverse security devices across multiple networks. By implementing standardized communication protocols and automated discovery mechanisms, the intermediary enables comprehensive security coverage while hiding the underlying complexity from operators.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If static security policies are used to protect the network, then device complexity is reduced, but adaptability to new threats deteriorates

Engineering Contradiction:
Improvepolicy management complexityVSAvoidadaptability to new threats
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The security management system implements dynamic policy generation and updates based on real-time threat intelligence and network conditions. Security policies are automatically adjusted and pushed to devices without requiring manual reconfiguration, enabling the system to adapt to new threats while maintaining simple policy management through automated processes. The dynamic nature of the system allows continuous adaptation without increasing operational complexity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12483600B2System and method for utilization of threat data for network security
Publication Date: 2025.11.25 LEVEL 3 COMMUNICATIONS LLC
  • US12483600B2 patent drawing
  • US12483600B2 patent drawing
  • US12483600B2 patent drawing

AI summary

Aspects of the present disclosure involve utilizing network threat information to manage one or more security devices or policies of a communication network. The security system may receive threat intelligence data or information associated with potential threats to a communications network and process the threat intelligence data to determine one or more configurations to apply to security devices of a network. The system may then generate a rule or action to respond to the identified attack, such as a firewall rule for a firewall device to block traffic from the source of the attack. The threat intelligence information may include a confidence score indicating a calculated confidence in the identification of the malicious communications, which may be utilized by the system to determine the type of action taken on the security devices of the network in response to the information or data.