Behavior-Based Network Policy Engine for SDN Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Statically configured firewall devices in network perimeters can create bottlenecks and inconsistencies in SDN environments, as they allow maximum access based on IP addresses rather than specific service behaviors, leading to inefficient network security and traffic management.
Innovation Solution
Implementing a system with a policy engine and context engine that determines network policies based on requested behaviors, using an application extension to authenticate and identify users and services, and providing dynamic policy rules to SDN switches to secure the network by allowing minimal access until authentication is verified, thereby routing traffic through authorized network paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If statically configured firewall devices are deployed to secure the network perimeter, then network security is improved, but network traffic bottlenecks and device complexity increase
Solution Approach 1:
The patent extracts the security policy decision-making function from traditional statically configured firewall devices and relocates it to a centralized controller. This separation allows the network devices to focus on simple packet forwarding while the controller handles complex security policy determination, thereby reducing device complexity at network nodes while maintaining or improving overall network security through centralized intelligent control
Solution Approach 2:
The patent introduces a centralized controller as an intermediary between network devices and security policies. This mediator receives service requests, determines appropriate security policies, and distributes them to network devices. The intermediary handles the complexity of security policy management centrally, eliminating the need for each network device to independently manage complex security configurations, thus reducing device complexity while maintaining security
2Ease of operation
If statically configured firewall devices allow maximum access based on IP addresses, then ease of operation is improved, but network security precision deteriorates
Solution Approach 1:
The patent transforms static IP-based access control into dynamic service behavior-based policy control. Instead of fixed rules based solely on IP addresses, the system dynamically determines security policies based on actual service requests and behaviors. This dynamic approach maintains ease of operation through automated policy determination while significantly improving security precision by adapting policies to actual traffic patterns and service requirements
Solution Approach 2:
The patent changes the fundamental parameter for security policy determination from static IP addresses to dynamic service behavior characteristics. By monitoring and analyzing service requests, the system extracts behavioral parameters (such as service type, request patterns, and communication patterns) to determine appropriate security policies. This parameter change enables both ease of operation through automated analysis and high precision in security enforcement
3Reliability
If packet inspection devices are deployed to identify safe traffic, then network security is improved, but network traffic speed and productivity deteriorate
Solution Approach 1:
The patent implements preliminary action by pre-determining security policies based on service requests before actual packet inspection is needed. The centralized controller analyzes service requests and establishes security policies in advance, allowing network devices to forward packets according to pre-established rules rather than performing complex inspection on every packet. This preliminary policy determination maintains high network security while preserving traffic speed by reducing real-time inspection overhead
Data Source
AI summary
In some examples, a system receives a context of an application to request a set of network traffic, the context including a requested behavior of a service enabled by the application, and provides a policy to a network device of a network, the policy to regulate the set of network traffic based on the context, the policy provided to the network device to cause the network device to route the set of network traffic based on applying the policy, the routing comprising forwarding the set of network traffic to a destination or denying transmission of the set of network traffic to the destination.


