Dynamic Application Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies struggle to validate connections between applications effectively, leading to false negatives due to rigid policy definitions that do not account for application version changes or similarities, resulting in unauthorized communications.

Innovation Solution

A system that uses application fingerprints and statistical analysis to enforce security policies, allowing updates to encompass new versions of applications while maintaining security integrity by defining and applying policies flexibly across various instances of an application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security policies define applications narrowly with specific identifiers, then security precision is improved, but adaptability deteriorates causing false negatives when applications update

Engineering Contradiction:
Improvesecurity precisionVSAvoidadaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transforms the security policy approach from using fixed parameters (specific application identifiers, versions, and configurations) to using dynamic parameters (behavioral characteristics, communication patterns, and functional properties). This allows the same security policy to adapt to application updates while maintaining precision in identifying authorized applications through their operational behavior rather than static identifiers.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic monitoring and evaluation of application behavior to determine policy compliance. Instead of static policy definitions that break when applications update, the system continuously observes application characteristics and compares them against security policies, enabling the policy enforcement mechanism to adapt to legitimate application changes while maintaining security precision.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If security policies are updated frequently to track application versions, then adaptability is improved, but system complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where the security system automatically monitors application behavior, extracts relevant characteristics, and evaluates compliance against security policies without requiring manual policy updates. The system autonomously adapts to application changes by observing behavioral patterns, eliminating the need for frequent manual policy revisions and reducing administrative complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates continuous feedback loops where application behavior is monitored, evaluated against security policies, and used to dynamically adjust policy enforcement decisions. This feedback mechanism enables the system to adapt to application updates automatically, reducing the need for manual policy maintenance and simplifying the overall system operation.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If host-based firewalls monitor connections in isolation, then device independence is improved, but security effectiveness deteriorates due to limited visibility

Engineering Contradiction:
Improvedevice independenceVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges the security monitoring capabilities across multiple hosts by collecting and correlating connection data from different system components. The security policy enforcement mechanism integrates information from source and destination hosts, combining their independent monitoring data to form a comprehensive view of application behavior, thereby improving security effectiveness while maintaining the operational independence of individual hosts.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11863662B2Automatic network application security policy expansion
Publication Date: 2024.01.02 ZSCALER INC
  • US11863662B2 patent drawing
  • US11863662B2 patent drawing
  • US11863662B2 patent drawing

AI summary

A system validates the establishment and/or continuation of a connection between two applications over a network. The system uses network application security rules to allow or disallow connections between the two applications. Those rules include definitions of the source and destination applications to which the rules apply. The system automatically updates the application definitions over time to encompass new versions of the applications covered by the security rules, but without encompassing other applications. The system is then capable of applying the updated rules both to the original applications and to the updated versions of those applications. This process enables the security rules to maintain security over time in a way that is consistent with the original intent of the rules even as applications on the network evolve.