Endpoint Transformation for Network Security Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for networks with numerous endpoints require manual generation and application of massive numbers of rules, leading to significant processing and storage resource utilization, as each endpoint pair needs a separate security policy due to varying network traffic patterns.

Innovation Solution

The endpoint transformation process reduces the number of network endpoints by combining or splitting them into transformed endpoints, allowing for the determination of similarity metrics and efficient management of security policies, which are then deployed based on connectivity vectors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate security policies are generated for each endpoint pair, then network security coverage is improved, but processing and storage resource utilization increases significantly

Engineering Contradiction:
Improvenetwork security coverageVSAvoidprocessing and storage resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines multiple endpoints into transformed endpoints by analyzing connectivity vectors and traffic patterns. Endpoints with similar connectivity characteristics are merged into single transformed endpoints, allowing security policies to be applied to groups rather than individual endpoints, thereby reducing the total number of policies needed while maintaining security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates transformed endpoints that represent multiple original endpoints with similar security requirements. A single security policy deployed to a transformed endpoint effectively secures all underlying endpoints, making the security policy universal across multiple targets and reducing redundant policy generation and management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If manual generation of security rules is performed for each endpoint, then security policy precision is improved, but device complexity and time consumption increase

Engineering Contradiction:
Improvesecurity policy precisionVSAvoidsecurity management complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system automatically generates security policies by analyzing connectivity vectors and traffic patterns between endpoints. The transformation process and policy generation are performed autonomously without manual intervention, reducing complexity while maintaining precision through data-driven analysis of actual network behavior.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs endpoint transformation and security policy generation in advance before actual security enforcement is needed. By pre-analyzing connectivity patterns and pre-generating policies for transformed endpoints, the system reduces the complexity of real-time security management while ensuring precise policy application.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security policies are deployed to all endpoints individually, then security coverage is improved, but deployment time and resource utilization worsen

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy deployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Multiple endpoints are merged into transformed endpoints based on connectivity vector analysis. Security policies are deployed to these transformed endpoints rather than individually to each original endpoint, significantly reducing deployment time while maintaining comprehensive security coverage through the representative nature of transformed endpoints.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10944723B2Systems and methods for managing endpoints and security policies in a networked environment
Publication Date: 2021.03.09 FORTINET INC
  • US10944723B2 patent drawing
  • US10944723B2 patent drawing
  • US10944723B2 patent drawing

AI summary

Systems, methods, and apparatuses enable deploying and executing a security policy on endpoints in a network. In an embodiment, a security orchestrator determines a set of endpoints in a network and determines transformed endpoints from the determined set of endpoints through an endpoint transformation process. The security orchestrator determines a connectivity vector for at least a first transformed endpoint and a second transformed endpoint, where the connectivity vector includes properties associated with the corresponding transformed endpoint. Using the properties from the connectivity vector of the first transformed endpoint, a security policy is generated and deployed to the first transformed endpoint. Based on a comparison of the connectivity vectors of the first and second transformed endpoints indicating a similarity between the first and second transformed endpoints, the security policy is further deployed to the second transformed endpoint.