Dynamic Access Control List Generation via Policy Enforcement Point Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional access control systems in large IP networks face challenges due to manual management of access control lists (ACLs), leading to errors and maintenance issues, as spatial relationships between ACLs are not explicitly connected to the services they protect, and changes in services do not affect the ACLs accordingly.
Innovation Solution
A method and system for dynamically creating network access control lists using resource descriptions and policy enforcement point graphs to generate ACLs, which includes identifying paths between computing devices, discarding unauthorized paths, and generating ACLs based on permitted and desired access information to control network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual management and creation of ACLs is used in large IP networks, then ACL configuration can be performed with existing tools, but numerous errors and maintenance issues occur due to the large number of ACLs and lack of explicit connection to services
Solution Approach 1:
The system enables self-service by having the network device automatically generate ACL entries based on observed traffic flows. The device monitors traffic patterns and autonomously creates appropriate ACL rules without requiring manual intervention, thereby reducing errors while managing large numbers of ACLs efficiently
Solution Approach 2:
The system implements feedback mechanisms where the network device continuously monitors traffic flows and uses this information to dynamically adjust and update ACL configurations. This closed-loop approach ensures ACLs remain aligned with actual service requirements, reducing maintenance issues while handling network complexity
2Adaptability or versatility
If manual ACL changes are performed by the ACL management team, then ACL updates can be made, but significant opportunities for error occur because team members may forget that a particular traffic flow is possible
Solution Approach 1:
The system replaces the mechanical manual process of ACL configuration with an automated electronic system. The network device automatically generates and updates ACL entries based on observed traffic flows, eliminating human memory limitations and errors while maintaining the flexibility to adapt to changing network conditions
3Ease of manufacture
If traditional manually configured ACLs are used, then ACLs can be created with basic tools, but they bear no explicit connection to the service or environment they are tasked to protect, leading to significant ACL maintenance issues
Solution Approach 1:
The system transforms static manually-configured ACLs into dynamic automatically-generated ACLs. The ACL entries are continuously updated based on real-time traffic flow observations, ensuring they remain aligned with current service requirements. This dynamic approach simplifies maintenance by eliminating the need for manual updates while preserving ease of initial deployment
Solution Approach 2:
The system performs preliminary action by pre-generating ACL entries based on observed traffic patterns before manual intervention is needed. The network device proactively creates and updates ACL rules in advance, ensuring security policies are already in place and aligned with service requirements before maintenance issues can arise
Data Source
AI summary
A method for dynamically creating network access control lists includes, by a processor receiving a request for an access control list (ACL). The method further includes, in response to receiving the request for the ACL: receiving a plurality of resource description from a first data source, receiving a policy enforcement point (PEP) graph for a network from a second data source, and using the plurality of resource descriptions and the PEP graph to generate the ACL, wherein the ACL comprises at least one policy for controlling network traffic through a PEP of the network. Each of the plurality of resource descriptions is associated with a plurality of computing devices in the network, and includes one or more of the following: information corresponding to an Internet Protocol definition of a computing device, information corresponding to desired access of the computing device, and information corresponding to permitted access of the computing device.


