Compliance-Based Network Traffic Filtering for Brownfield Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network systems struggle to effectively filter network traffic based on the compliance status of communication endpoints, especially in 'brownfield systems' that lack support for context checks or have limited access to device compliance information.
Innovation Solution
A method for providing filter rules that depend on the compliance status of communication endpoints, allowing for the adjustment and application of filter rules based on the conformance status of nodes in a communication connection, thereby ensuring secure and compliant network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If compliance status checking is implemented in brownfield systems, then network security is improved, but system complexity increases due to lack of native support for context checks
Solution Approach 1:
The patent introduces an intermediary component that acts as a bridge between brownfield systems lacking native compliance checking capabilities and the required security policies. This intermediary translates compliance requirements into filter rules that can be enforced without modifying the underlying brownfield system architecture, thereby improving security while managing complexity through layering.
Solution Approach 2:
The compliance checking functionality is segmented into separate, manageable components including policy definition modules, compliance status determination modules, and filter rule generation modules. This segmentation allows the complex compliance checking task to be distributed across independent components that can be implemented and maintained separately in brownfield environments.
2Reliability
If filter rules are continuously updated based on compliance status, then network traffic filtering effectiveness is improved, but processing time increases
Solution Approach 1:
The system performs preliminary actions by pre-defining compliance policies and pre-generating filter rules based on anticipated compliance states. When compliance status changes are detected, only the specific filter rules affected by the change are updated rather than reprocessing all rules, significantly reducing processing time while maintaining filtering effectiveness.
Solution Approach 2:
The compliance status checking and filter rule updating is implemented as a periodic process rather than continuous real-time monitoring. Filter rules are updated at scheduled intervals or triggered by specific events, balancing the need for current filtering effectiveness with the constraint of processing time and system resource availability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for providing at least one filter rule (aFR) for filtering network traffic between at least one first node (1) and at least one second node (2) of a communication connection, comprising the steps of: - using (S2) at least one conformity status of the first node (1) and/or the second node (2), - defining (S3) the at least one filter rule (aFR) based on the at least one conformity status, wherein the defining (S3) of the at least one filter rule (aFR) comprises: o adapting (S3a) at least one existing filter rule (FR), and - providing (S4) the at least one filter rule (aFR). The invention also relates to a computer program product, a component and a higher-level system.