Workflow Scheme for Dynamic Cyber Protection Resource Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber security solutions for communication networks face challenges in managing and configuring security resources, particularly in large-scale networks, due to complexity and the need for customization, leading to overcomplicated systems that are inflexible and prone to errors, which cannot rapidly adapt to dynamic cyber threats like DDoS burst attacks.

Innovation Solution

A method and system that utilize a workflow scheme with operation regimens and triggering criteria to dynamically provision and operate protection resources, allowing for flexible and automated defense against cyber-attacks by generating and assigning workflow schemes to protected entities, monitoring for trigger events, and adjusting operation regimens based on detected threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security resources are deployed in communication networks to combat cyber threats, then security protection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security resources into multiple protection resources (detection resources, mitigation resources, blocking resources) distributed across different network locations and tiers. Each resource operates independently with specific functions, allowing the system to maintain high security capability while managing complexity through modular organization rather than monolithic structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a unified security system where multiple protection resources serve universal functions across different network domains. The same types of resources (detectors, mitigators, blockers) can be deployed at various tiers (edge, backbone, cloud) and adapted to different threat scenarios, reducing overall system complexity through standardized multi-functional components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple security systems are incorporated into networks to combat increasing cyber security threats, then security coverage is improved, but manual configuration complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidmanual configuration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automated provisioning and configuration mechanisms where protection resources self-configure based on pre-defined policies and workflows. The system automatically detects threats, selects appropriate mitigation actions, and configures resources without requiring manual administrator intervention for each security event, thereby maintaining comprehensive security coverage while eliminating manual configuration complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs pre-configured workflows and operation regimens that define security responses in advance. When threats are detected, the system executes pre-planned actions rather than requiring real-time manual configuration. This preliminary preparation of security policies and response procedures enables broad security coverage while keeping operational complexity low.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If security resources are manually configured to capture all possible attack scenarios, then detection accuracy is improved, but configuration time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements continuous monitoring and feedback mechanisms where detection resources collect data about network traffic and threats, which is then analyzed to automatically adjust and refine detection rules. This feedback loop enables the system to maintain high detection accuracy by continuously learning from observed threats without requiring manual reconfiguration for each new attack pattern.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates dynamic security configurations that automatically adapt to changing threat conditions. Instead of static manual configurations, the system dynamically adjusts detection parameters, resource allocation, and mitigation strategies based on real-time threat assessment, maintaining high detection accuracy while eliminating time-consuming manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If security systems are designed with many features to fit various organizational needs, then adaptability is improved, but system manageability deteriorates

Engineering Contradiction:
Improveadaptability to organizational needsVSAvoidsystem manageability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent enables local customization of security resources based on specific organizational needs and network characteristics. Different protection resources can be configured with locally appropriate parameters and policies tailored to specific domains (edge, backbone, cloud) and organizational requirements, while the overall system remains manageable through standardized control mechanisms and automated provisioning.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10033758B2System and method for operating protection services
Publication Date: 2018.07.24 RADWARE LTD
  • US10033758B2 patent drawing
  • US10033758B2 patent drawing
  • US10033758B2 patent drawing

AI summary

A method and system for operating protection services to provide defense against cyber-attacks. The comprises generating a workflow scheme assigned to at least one protected entity, wherein the workflow scheme includes at least one operation regimen and triggering criteria associated with the at least one operation regimen; monitoring at least a plurality of protection resources to detect at least one trigger event; determining if the at least one detected trigger event satisfies the triggering criteria associated with the at least one operation regimen; and changing a state of the at least one operation regimen when the at least one detected trigger event satisfies the at least one triggering criterion, thereby causing provisioning and operating of at least one protection resource of the plurality of protection resources, wherein the provisioning is based on contents defined in the at least one operation regimen.