Automated Network Perimeter Definition via Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for determining a network perimeter for organizations are often incomplete or outdated, requiring significant technical expertise and frequent updates, which can lead to ineffective network security policies and vulnerabilities to unauthorized access.

Innovation Solution

A system that automatically determines a network perimeter by analyzing connection data from client devices using a machine learning-based model, which receives input on network zones and outputs security scores to recommend an ideal network perimeter, with continuous adjustment based on new connection data and administrator feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network administrators manually define network perimeter using network zones, then network security policies can be implemented, but significant technical expertise is required and the information becomes outdated frequently

Engineering Contradiction:
Improvenetwork perimeter accuracyVSAvoidnetwork administrator effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically determines network perimeter by analyzing connection data from client devices without requiring manual intervention from network administrators. The automated system service monitors connection requests, identifies trusted network zones, and maintains perimeter definitions autonomously, eliminating the need for administrators to manually define and update network zones while ensuring continuous accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of administrators defining network perimeters with an automated computational system that analyzes connection data. The system uses automated algorithms to process connection requests, identify patterns, and determine trusted network zones, substituting human expertise and manual updates with automated data-driven decision-making

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If network administrators diligently update network perimeter information regularly, then the network perimeter remains accurate, but the process requires significant time and expertise

Engineering Contradiction:
Improvenetwork perimeter currencyVSAvoidupdate maintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system continuously monitors connection data from client devices in real-time, automatically updating network perimeter definitions without interruption. The automated system maintains continuous analysis of connection requests and dynamically adjusts perimeter information, ensuring constant currency without requiring periodic manual updates that consume administrator time

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The automated system self-updates network perimeter information by continuously analyzing connection data and identifying trusted zones. The system serves itself by autonomously maintaining accurate perimeter definitions without requiring external intervention or time investment from network administrators for updates

Inventive Principle:
Principle #25Self-service

3Ease of operation

If automated system analyzes connection data to determine network perimeter, then technical expertise requirement is reduced, but the system requires processing of large volumes of connection data

Engineering Contradiction:
Improvetechnical expertise requirementVSAvoidconnection data volume
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The system extracts only the essential and relevant features from large volumes of connection data, such as source IP addresses, connection patterns, and authentication outcomes. By extracting key indicators of trusted network zones rather than processing entire raw datasets, the system reduces the effective data volume requiring detailed analysis while maintaining accuracy in perimeter determination

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250106184A1Automated creation of trusted network perimeter
Publication Date: 2025.03.27 OKTA INC
  • US20250106184A1 patent drawing
  • US20250106184A1 patent drawing
  • US20250106184A1 patent drawing

AI summary

A system generates network perimeter for an organization based on the connection data. The system builds a model, for example, a machine learning based model configured to receive a network zone as input and output a score indicating security of the network zone. The system receives information describing connection requests received from client devices associated with the organization. The system adjusts parameters of the machine learning based model based on information describing the connection requests. The adjusting of the machine learning based model improves the accuracy of prediction based on the information describing the connection requests. The system determines a network perimeter for the organization using the machine learning based model. The network perimeter may be used for implementing a network policy for the organization based on the determined network perimeter.