Dynamic Application Security Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security technologies struggle to validate connections between applications effectively, leading to false negatives due to rigid policy definitions that do not account for application version changes or similarities, resulting in unauthorized communications.
Innovation Solution
A system that uses application fingerprints and statistical analysis to enforce security policies, allowing updates to encompass new versions of applications while maintaining security integrity by defining and applying policies flexibly across various instances of an application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security policies define applications narrowly with specific identifiers, then security precision is improved, but adaptability deteriorates causing false negatives when applications update
Solution Approach 1:
The patent transforms the security policy approach from using fixed parameters (specific application identifiers, versions, and configurations) to using dynamic parameters (behavioral characteristics, communication patterns, and functional properties). This allows the same security policy to adapt to application updates while maintaining precision in identifying authorized applications through their operational behavior rather than static identifiers.
Solution Approach 2:
The patent introduces dynamic monitoring and evaluation of application behavior to determine policy compliance. Instead of static policy definitions that break when applications update, the system continuously observes application characteristics and compares them against security policies, enabling the policy enforcement mechanism to adapt to legitimate application changes while maintaining security precision.
2Adaptability or versatility
If security policies are updated frequently to track application versions, then adaptability is improved, but system complexity increases
Solution Approach 1:
The patent implements a self-service mechanism where the security system automatically monitors application behavior, extracts relevant characteristics, and evaluates compliance against security policies without requiring manual policy updates. The system autonomously adapts to application changes by observing behavioral patterns, eliminating the need for frequent manual policy revisions and reducing administrative complexity.
Solution Approach 2:
The patent incorporates continuous feedback loops where application behavior is monitored, evaluated against security policies, and used to dynamically adjust policy enforcement decisions. This feedback mechanism enables the system to adapt to application updates automatically, reducing the need for manual policy maintenance and simplifying the overall system operation.
3Ease of operation
If host-based firewalls monitor connections in isolation, then device independence is improved, but security effectiveness deteriorates due to limited visibility
Solution Approach 1:
The patent merges the security monitoring capabilities across multiple hosts by collecting and correlating connection data from different system components. The security policy enforcement mechanism integrates information from source and destination hosts, combining their independent monitoring data to form a comprehensive view of application behavior, thereby improving security effectiveness while maintaining the operational independence of individual hosts.
Data Source
AI summary
A system validates the establishment and/or continuation of a connection between two applications over a network. The system uses network application security rules to allow or disallow connections between the two applications. Those rules include definitions of the source and destination applications to which the rules apply. The system automatically updates the application definitions over time to encompass new versions of the applications covered by the security rules, but without encompassing other applications. The system is then capable of applying the updated rules both to the original applications and to the updated versions of those applications. This process enables the security rules to maintain security over time in a way that is consistent with the original intent of the rules even as applications on the network evolve.


