Connectivity Manager for Automated Access-Control Rule Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing connectivity requests in computer networks is challenging due to the need for constant updates in access control rule-sets to accommodate changing business needs, with network applications requiring multiple connections that can be blocked by access-control devices, making it difficult for application owners to ensure proper connectivity across security gateways.
Innovation Solution
A connectivity manager system that generates a connectivity specification for applications, recognizes and maps access-control devices and rules, and monitors changes to ensure seamless connectivity by automatically updating and amending access-control rules to align with connectivity requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access control rule-sets are constantly updated to accommodate changing business needs, then connectivity requirements are satisfied, but the complexity of managing multiple security gateways increases
Solution Approach 1:
The patent introduces a connectivity manager as an intermediary system that sits between the application layer and multiple access-control devices. This manager automatically discovers the application's connectivity requirements, translates them into appropriate access-control rules, and distributes them to the relevant security gateways. By mediating between business needs and security enforcement, it eliminates the manual complexity of constantly updating rule-sets across multiple devices while maintaining high adaptability to changing connectivity requirements.
Solution Approach 2:
The system enables self-service through automated discovery and rule generation. The connectivity manager automatically discovers which access-control devices are involved in an application's connectivity path, generates the necessary rules based on the application's requirements, and pushes them to the appropriate devices without human intervention. This self-service capability allows the system to adapt to changing business needs automatically, removing the manual burden from security administrators.
2Stability of the object's composition
If manual management of access-control rules is performed, then rule-set consistency can be maintained, but time consumption and operational efficiency decrease
Solution Approach 1:
The connectivity manager performs preliminary actions by automatically discovering and mapping the connectivity requirements of applications before any connectivity issues arise. It proactively identifies which access-control devices need rules, generates the appropriate rules in advance, and pushes them to the devices before the application needs to connect. This preliminary automation maintains rule-set consistency across all devices without requiring manual intervention, eliminating both time loss and consistency errors.
Solution Approach 2:
The system implements feedback mechanisms where the connectivity manager continuously monitors application connectivity status and automatically adjusts access-control rules based on observed connectivity patterns and failures. This closed-loop feedback ensures rule-set consistency is maintained dynamically across multiple devices, with the system self-correcting any inconsistencies without manual intervention, thereby eliminating the time traditionally spent on manual rule management.
3Productivity
If automated rule generation is implemented, then management efficiency improves, but the risk of security policy violations increases
Solution Approach 1:
The connectivity manager is designed as a universal system that handles multiple functions: it discovers applications, maps their connectivity requirements, generates access-control rules, pushes them to devices, and monitors compliance. By consolidating these functions in a single centralized system, it ensures that security policies are generated and enforced consistently across all access-control devices, maintaining both high management efficiency and reliable security policy compliance through unified control.
Solution Approach 2:
The system uses feedback mechanisms to continuously verify that generated rules comply with security policies. The connectivity manager monitors the deployment and effectiveness of automated rules, comparing them against defined security requirements and application connectivity patterns. This feedback loop allows the system to detect and correct potential policy violations automatically, maintaining security compliance while enjoying the efficiency benefits of automation.
Data Source
AI summary
There are provided a computer-implemented connectivity manager and a method of managing connectivity between resources in a computer network using the connectivity manager. The method comprises: generating a connectivity specification of a given application, said specification comprising one or more connections generated in accordance with received by the connectivity manager user's definition of network resources and connections therebetween required to the given application, each connection characterized by one or more source resources, one or more destination resources and services therebetween; recognizing, by the connectivity manager, all access-control devices among the plurality of access-control devices, which are involved in controlling all connections comprised in said connectivity specification; identifying, by the connectivity manager, in each of the recognized access-control devices, access-control rules engaged in control of connections comprised in said connectivity specification; and mapping, by the connectivity manager, said connections comprised in said connectivity specification to the identified engaged access-control rules.


