Four Dimensional Network Session Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current firewall systems are ineffective in automatically defining and enforcing network sessions, as they rely on manual configuration and are prone to being bypassed by hackers, leading to outdated security measures.
Innovation Solution
Implementing a system that automatically defines and enforces network sessions based on four dimensions of segmentation (source, destination, port, and protocol) using a processing resource to monitor and classify network traffic, allowing for dynamic policy updates and enforcement without manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual firewall configuration is used to block prohibited URLs, then security control is implemented, but the system becomes outdated easily and is prone to being bypassed by hackers
Solution Approach 1:
The system performs self-service by automatically monitoring network traffic, extracting four-dimensional session definitions, classifying them as prohibited or allowed, and dynamically updating firewall rules without manual intervention. This automated self-updating mechanism ensures the security system remains current with evolving threats while maintaining reliable security control.
2Ease of operation
If manual firewall rules are configured for each URL, then explicit control is achieved, but the device complexity and maintenance burden increase
Solution Approach 1:
Instead of manually configuring individual firewall rules for each URL, the system creates copies of four-dimensional session definitions from monitored network traffic. These session definition copies are automatically classified and used to generate firewall rules, dramatically reducing configuration complexity while maintaining precise control over network access.
Solution Approach 2:
The system implements a universal classification mechanism that handles multiple types of network traffic and session definitions through a single automated process. The four-dimensional session definition structure (source IP, destination IP, source port, destination port) serves as a universal template that can represent any network connection, eliminating the need for separate manual configurations for different URL types.
3Adaptability or versatility
If dynamic firewall decisions are made for unclassified URLs, then flexibility is improved, but the system becomes prone to security gaps
Solution Approach 1:
The system implements feedback by continuously monitoring network traffic, classifying observed sessions, and using these classifications to update firewall rules. This closed-loop feedback mechanism ensures that dynamic decisions are based on actual observed traffic patterns rather than static pre-configured rules, improving both flexibility and security consistency simultaneously.
Data Source
AI summary
Various embodiments provide systems and methods for automatically defining and enforcing network sessions based upon at least four dimensions of segmentation.


