Adaptive Security Policy Placement in Distributed Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing distributed firewalls lack an adaptive mechanism to optimally select and place security policies, leading to inefficiencies and potential vulnerabilities in network security.

Innovation Solution

A method that involves a controller determining optimal enforcement points within a network based on estimated flow costs, and sending instructions to apply security policies at these selected points, using data processing units (DPUs) and extended Berkley Packet Filters (eBPFs) for security operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are distributed across multiple enforcement points, then security coverage and reliability are improved, but device complexity and difficulty of policy optimization increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy optimization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A controller is introduced as an intermediary component that receives security policies, determines optimal enforcement points based on network topology and flow costs, and distributes optimized policies to enforcement points. This mediator simplifies the complexity of policy optimization by centralizing the decision-making logic rather than requiring each enforcement point to independently optimize its own policy placement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments security policy enforcement into multiple distributed enforcement points across the network, each responsible for enforcing policies at specific locations. This segmentation improves security coverage by placing protection closer to data flows while the controller manages the overall optimization coordination.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security policies are applied at all network nodes, then security effectiveness is improved, but resource utilization efficiency deteriorates

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies different security policy enforcement strategies at different network locations based on local characteristics such as flow costs, network topology, and traffic patterns. Rather than uniform enforcement, the controller determines optimal enforcement points for each policy based on local conditions, improving resource utilization while maintaining security effectiveness.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts policy enforcement parameters based on changing network conditions including flow costs, topology changes, and traffic patterns. The controller reoptimizes policy placement by modifying enforcement parameters to adapt to current network state, ensuring efficient resource utilization while maintaining security effectiveness.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If static security policies are used, then ease of operation is improved, but adaptability to changing network conditions and threats deteriorates

Engineering Contradiction:
Improvepolicy management simplicityVSAvoidadaptability to network changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system transitions from static security policies to dynamic policy optimization where the controller continuously monitors network conditions including flow costs, topology changes, and traffic patterns. The system dynamically adjusts policy enforcement points and parameters to adapt to changing network state while maintaining ease of operation through automated optimization.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The controller receives feedback about network conditions such as flow costs, policy effectiveness, and topology changes, and uses this information to optimize policy placement. This feedback mechanism enables the system to adapt to changing network conditions and threats while maintaining operational simplicity through automated decision-making.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250039239A1Adaptive policy generation in distributed security fabrics
Publication Date: 2025.01.30 CISCO TECHNOLOGY INC
  • US20250039239A1 patent drawing
  • US20250039239A1 patent drawing
  • US20250039239A1 patent drawing

AI summary

A system and method are provided for placing security operations at selected enforcement points in a distributed security fabric. The enforcement points at which the security operations are placed can be endpoints, nodes, and/or network devices within the network. The security operations can be updated by monitoring data flows through the network to generate network data, and then determining, based on the network data, one or more changes to the security operations, based on the generated network data. Recommended changes can be obtained by applying the network data to a machine-learning model that indicates suspicious data packets (e.g., disseminates packets suspected of being malicious from normal traffic) and crafts new policies to deny the suspicious data packets. Performance of the network can also be improved by analyzing the security operations for redundancies and/or inefficiencies and modifying the security operations to mitigate them.