Access Control Graph for Network Security Path Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems lack efficient methods for identifying and validating network security paths in multi-node networks, which are crucial for ensuring compliance with security protocols and policies, leading to potential vulnerabilities and compliance failures.
Innovation Solution
The generation of an Access Control Graph (ACG) based on a Network Access Control List (NACL) to model nodes and communicative couplings, classify nodes and edges, and identify and validate paths for compliance with pre-defined security policies, using graph routing techniques and classification features such as authentication, authorization, and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security systems use traditional methods for identifying and validating security paths, then the systems can operate with simpler structures, but the systems fail to ensure compliance with security protocols and policies
Solution Approach 1:
The patent segments the network security validation process into distinct components: generating an access control graph from NACL rules, classifying nodes and edges with security attributes, identifying paths using graph routing algorithms, and validating paths against security policies. This segmentation allows each component to be optimized independently while ensuring comprehensive security compliance.
Solution Approach 2:
The patent introduces an access control graph as an intermediary data structure that bridges the gap between NACL rules and security path validation. The graph serves as a mediator that transforms complex security policies into structured node-edge relationships, enabling efficient path identification and validation while maintaining reliability.
2Reliability
If network security systems implement comprehensive path validation, then security compliance is ensured, but the complexity of path compliance validation increases
Solution Approach 1:
The patent changes the parameters of path validation by classifying nodes and edges with security attributes (authentication, authorization, encryption) and using these classified parameters to systematically validate paths. This approach transforms complex validation into a structured process that checks specific parameters against security policies, reducing overall complexity while maintaining comprehensive compliance.
Solution Approach 2:
The patent performs preliminary classification of nodes and edges with security attributes before path validation. By pre-processing the access control graph with classification information, the system prepares the data structure in advance, making the subsequent path validation more efficient and less complex while ensuring comprehensive security compliance.
3Reliability
If network security systems identify all security paths, then complete compliance validation is achieved, but the time and resources required for validation increase
Solution Approach 1:
The patent replaces traditional mechanical path traversal methods with graph routing algorithms that leverage the structured access control graph. This substitution enables the system to identify all security paths efficiently by utilizing graph theory optimizations, achieving complete compliance validation without proportionally increasing validation time.
Solution Approach 2:
The patent performs preliminary generation and classification of the access control graph before path identification. By preparing the graph structure and security attributes in advance, the system reduces the time required for actual path identification and validation, achieving complete compliance checking with minimized time loss.
Data Source
AI summary
Embodiments herein may relate to a technique for identification and verification of compliance with one or more pre-defined security policy sets for a network. Specifically, embodiments may include generation of an access control graph (ACG) that relates to the network. One or more paths of the ACG may be identified, and then compared against the pre-defined security policy sets. Other embodiments may be described or claimed.


