Context-Aware Application Flow Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of users and devices accessing applications across various networks and contexts complicates the implementation of secure and nuanced access policies, as existing technologies lack granular decision-making capabilities to handle trusted and untrusted user-device combinations effectively.

Innovation Solution

A system that employs an active threat detection agent to analyze application flows based on user context, device context, and application context, using machine learning models like random forests and isolation forests to classify flows and direct them according to application access policies, with an identity services engine applying appropriate restrictions or authorizations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If granular context-based access policies are implemented to improve security, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity services engine as an intermediary component that centralizes the complex task of analyzing user context, device context, and application context. This engine acts as a mediator between the threat detection agent and the access policy enforcement mechanisms, handling the computational complexity of context analysis and classification while allowing other system components to remain relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the access control functionality into distinct modular components: a threat detection agent for monitoring flows, an identity services engine for context analysis and classification, and policy enforcement mechanisms. This segmentation allows each component to specialize in specific tasks, improving overall security while making the complexity manageable through modular architecture.

Inventive Principle:
Principle #1Segmentation

2Manufacturing precision

If context analysis is performed on all application flows to improve access control precision, then manufacturing precision is improved, but use of energy increases

Engineering Contradiction:
Improveaccess control precisionVSAvoiduse of energy
Core Design Contradiction:
Manufacturing precisionVSUse of energy by moving object

Solution Approach 1:

The threat detection agent selectively applies context analysis to application flows based on detected anomalies or risk indicators. Rather than analyzing every flow with full context analysis, the system performs partial analysis on flows that exhibit suspicious characteristics, thereby achieving high access control precision for critical cases while reducing overall energy consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system applies different levels of analysis intensity to different application flows based on their characteristics. High-risk flows receive comprehensive context analysis with multiple classification models, while low-risk flows receive minimal or no analysis. This local differentiation of quality ensures precise access control where needed while conserving energy resources.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11388175B2Threat detection of application traffic flows
Publication Date: 2022.07.12 CISCO TECHNOLOGY INC
  • US11388175B2 patent drawing
  • US11388175B2 patent drawing
  • US11388175B2 patent drawing

AI summary

The present technology pertains to a system that routes application flows. The system can receive an application flow from a device by an active threat detection agent; analyze the application flow for user context, device context, and application context; classify the application flow based on the analysis of the application flow; and direct the application flow according to the classification of the application flow and an application access policy.