Threat Management Device Scaling Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional threat management systems face challenges in scaling their processing resources to handle large volumes of threat traffic during major attacks without wasting resources during low-traffic periods, leading to potential drops in both legitimate and attack traffic.
Innovation Solution
A method and system that dynamically adjust the number of threat management devices based on traffic volume, automatically assigning and directing packets to ensure no single device exceeds capacity, using a scaling module to enable or disable devices as needed and share state parameters for seamless integration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the number of threat management devices is increased to handle large volumes of threat traffic during major attacks, then the system can manage high-volume threat traffic without dropping legitimate traffic, but processing resources are wasted during low-traffic periods
Solution Approach 1:
The system dynamically adjusts the number of active threat management devices based on real-time threat traffic volume. A scaling module continuously monitors traffic levels and automatically enables or disables devices from the plurality of threat management devices, allowing the system to scale capacity up during major attacks and scale down during low-traffic periods, thus resolving the contradiction between maintaining high productivity and avoiding resource waste
Solution Approach 2:
The system changes the operational parameter of device quantity based on traffic conditions. By monitoring threat traffic volume and adjusting the number of active devices accordingly, the system adapts its processing capacity to match actual demand, preventing both overload during peak attacks and waste during low-traffic periods
2Loss of energy
If a single threat management device is used during low-traffic periods, then resource usage is minimized, but the device capacity is insufficient during major attacks leading to traffic drops
Solution Approach 1:
The system segments the threat management function across multiple devices in a plurality of threat management devices. Instead of relying on a single device, the system divides the workload across multiple units that can be individually enabled or disabled. This segmentation allows the system to use minimal resources during low-traffic periods while having the capacity to activate additional segments during major attacks, maintaining reliability without constant resource consumption
Solution Approach 2:
Each threat management device in the plurality is designed to be universally capable of handling threat traffic analysis and mitigation. The devices can function independently or in combination, allowing the system to use a single device during low-traffic periods for efficient resource usage, while any subset of the plurality can be activated during major attacks to ensure sufficient capacity and reliability
Data Source
AI summary
A method, system, and computer-implemented method to manage threats to a network is provided. The method includes receiving volume threat data that indicates a volume of threat data that needs to be managed by a threat management system having a plurality of threat management devices, determining a volume range from a plurality of volume ranges to which the received volume threat data belongs, determining a number of threat management devices of the plurality of threat devices needed to manage threat traffic associated with the volume range determined, and determining whether the number of threat management devices needed is different than a number of threat management devices currently being used to manage threat traffic. The method further includes selecting automatically threat management devices of the plurality of threat management devices to manage received threat data, in response to a determination that the number is different and based on the number determined, assigning automatically, each packet of the threat traffic to a group, each group corresponding to a threat management device of the selected threat management devices, and directing automatically each packet of the threat traffic to the threat management device that corresponds to the group to which the packet is assigned.


