Virtual Network Security Orchestration for Dynamic Threat Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network security techniques rely on expensive, pre-provisioned hardware appliances that are inefficient in dynamically adapting to changing threat landscapes and network traffic, leading to potential service disruptions and financial losses.

Innovation Solution

A system utilizing threat data feeders, a threat intelligence center, a core security advisor, virtual orchestrator, and SDN controller to gather and analyze threat information, dynamically deploy virtual appliances, and program virtual switches using network function virtualization and software defined networking for adaptive threat prevention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If pre-provisioned hardware appliances are used for network security, then security protection is provided, but the system cannot dynamically adapt to changing threats and network conditions

Engineering Contradiction:
Improvedynamic adaptability to threatsVSAvoidsecurity protection effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies dynamics by transitioning from static pre-provisioned hardware appliances to dynamic software-defined security functions that can be programmed and reconfigured in real-time. The SDN controller dynamically programs network devices with security policies based on current threat intelligence and network conditions, enabling the security system to adapt its behavior continuously rather than relying on fixed configurations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of security appliance provisioning from fixed hardware configurations to flexible software parameters. Security policies, threat signatures, and filtering rules are represented as programmable parameters that can be modified remotely and dynamically by the SDN controller based on evolving threats, rather than being hardcoded into hardware appliances.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If hardware appliances are over-provisioned to handle variable network traffic, then service continuity is maintained, but resource efficiency decreases

Engineering Contradiction:
Improveresource efficiencyVSAvoidservice continuity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies universality by creating a multi-functional software-defined security platform that can perform multiple security functions (firewalling, intrusion detection, threat blocking) through a single programmable system. Instead of requiring separate dedicated hardware appliances for each security function, the SDN controller can dynamically allocate and reconfigure security resources to handle various threats and traffic patterns using the same infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically scales security resource allocation based on actual network traffic and threat levels. The SDN controller monitors network conditions and adjusts the provisioning of security functions in real-time, allocating more resources during high-threat periods and reducing overhead during normal operations, thereby maintaining service continuity while improving resource efficiency.

Inventive Principle:
Principle #15Dynamics

3Reliability

If software is upgraded at periodic intervals, then new threat signatures are incorporated, but response time to emerging threats is delayed

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidresponse time to threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements continuous feedback loops where the SDN controller receives real-time threat intelligence from multiple sources, analyzes current threats, and immediately updates security policies and signatures. This feedback mechanism ensures that threat detection capabilities are continuously refreshed based on the latest threat information rather than waiting for periodic upgrade cycles, enabling rapid response to emerging threats.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by pre-positioning the SDN controller with update capabilities and maintaining continuous connections to threat intelligence sources. When new threats are detected, the controller can immediately push updated security signatures and policies to network devices without waiting for scheduled maintenance windows or periodic upgrade intervals, enabling proactive threat response.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If expensive hardware appliances are used, then security functionality is provided, but cost and complexity increase

Engineering Contradiction:
Improvesecurity functionalityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies copying by virtualizing security functions as software instances that can be replicated and distributed across standard network devices. Instead of relying on expensive proprietary hardware appliances, the system creates software copies of security functionality (firewalls, IDS, threat blockers) that run on commodity network equipment, significantly reducing hardware costs while maintaining security effectiveness through software-defined control.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3154236B1System and method for providing computer network security
Publication Date: 2021.10.06 WIPRO LTD
  • EP3154236B1 patent drawingFigure 1
  • EP3154236B1 patent drawingFigure 2~3
  • EP3154236B1 patent drawingFigure 4

AI summary

This disclosure relates generally to computer network, and more particularly to a system and method for providing computer network security. In one embodiment, a method is provided for providing computer network security. The method comprises gathering threat information from one or more sources, deriving security intelligence based on the threat information, determining a security measure based on the security intelligence, and dynamically applying the security measure to a computer network using a set of virtual appliances and a set of virtual switches.