Access Control Rule Segmentation for Network Intrusion Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network infrastructure faces capacity limitations in delivering access control rules efficiently, leading to increased susceptibility to cyber-attacks and decreased stability of client devices, as the number of access control rules exceeds the capacity of standard client devices like routers and switches.

Innovation Solution

A system and method for optimizing access control rules by generating and distributing rule data in the form of data buckets associated with ranges of destination port numbers, allowing for real-time updates and fine-grained access control, while monitoring and analyzing telemetry data to detect and prevent intrusions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If the number of access control rules is increased to provide fine-grained access control, then the access control precision is improved, but the client device stability deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidclient device stability
Core Design Contradiction:
Manufacturing precisionVSStability of the object's composition

Solution Approach 1:

The access control rules are segmented into multiple data buckets, where each bucket contains rules for a specific range of destination port numbers. This segmentation allows the rules to be organized in a manageable structure that can be efficiently processed by client devices without overwhelming them with a single large rule set, thereby maintaining device stability while providing fine-grained access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of organization by grouping access control rules according to destination port number ranges rather than simply listing all rules sequentially. This dimensional reorganization enables client devices to process and apply rules more efficiently, improving stability while maintaining the precision needed for fine-grained access control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If the number of access control rules is increased to enhance network security, then the security capability is improved, but the device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidclient device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By dividing the access control rules into data buckets organized by destination port number ranges, the system reduces the complexity burden on individual client devices. Each device only needs to process rules relevant to its port ranges, simplifying the overall device complexity while maintaining comprehensive network security through the complete rule set.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data bucket structure acts as an intermediary between the comprehensive access control rules and the client devices. This intermediary organization method allows secure rule distribution without directly exposing the full complexity of the rule set to each device, thereby enhancing security while managing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If access control rules are disseminated to more client devices, then the network coverage is improved, but the perimeter firewall overload increases

Engineering Contradiction:
Improvenetwork coverageVSAvoidfirewall capacity
Core Design Contradiction:
Adaptability or versatilityVSPower

Solution Approach 1:

The patent extracts the access control rule dissemination function from the perimeter firewall and distributes it to client devices. By giving client devices the capability to process and enforce access control rules locally, the system expands network coverage without concentrating all firewall processing capacity at a single perimeter location, thereby avoiding firewall overload.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Client devices are enabled to self-provision with access control rules and autonomously enforce them. This self-service capability allows devices to participate in security enforcement without requiring continuous intervention or processing capacity from the perimeter firewall, expanding network coverage while preserving firewall capacity for critical perimeter functions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11784974B2Method and system for intrusion detection and prevention
Publication Date: 2023.10.10 YAHOO ASSETS LLC
  • US11784974B2 patent drawing
  • US11784974B2 patent drawing
  • US11784974B2 patent drawing

AI summary

The present teaching generally relates to providing optimized access control rules. A request may be received from a client device. A determination may be made, based on the request, that an update is needed for access control rule information for the client device. Rule data may be generated. The rule data may include a plurality of data buckets each including one or more access control rules, each data bucket of the plurality being associated with a range of destination port numbers, and where each of the one or more access control rules comprise a set of tuples having a common source network and source port number, and one or more destination port numbers associated with the common source network and source port number. The rule data may be sent to the client device.