Granular Network Segmentation via Metadata-Driven Firewall Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, particularly firewalls, face challenges in managing large sets of rules and effectively segmenting data networks to prevent lateral movement of attackers within internal networks, leading to breaches and data theft.

Innovation Solution

The implementation of granular segmentation of data networks through the use of metadata-driven methods, where event metadata is used to identify workload types, generate declarative security policies, and configure network switches to enforce low-level firewall rules, thereby controlling communications between workloads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall rule management is used to control network traffic, then network security can be maintained, but the complexity of managing large sets of rules increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall rule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple isolated segments based on workload types and security requirements. By dividing the network into granular segments and applying firewall rules at the segment level rather than managing a single large rule set, the system reduces management complexity while maintaining security. Each segment enforces its own security policies independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary system that automatically generates and manages firewall rules based on metadata about workloads and network traffic patterns. This intermediary layer translates high-level security requirements into specific firewall rules, reducing the complexity of direct rule management while ensuring consistent security enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network segmentation is implemented to prevent lateral movement of attackers, then security against data breaches is improved, but the difficulty of detecting and measuring traffic patterns increases

Engineering Contradiction:
Improvesecurity against data breachesVSAvoidtraffic pattern detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously monitors network traffic patterns within segmented networks and automatically adjusts firewall rules based on detected anomalies. The system uses metadata from traffic flows to identify patterns and responds by modifying segmentation policies, creating a closed-loop system that improves detection capability while maintaining security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces manual traffic pattern analysis with automated metadata-driven systems that use compiler technology to generate and enforce security policies. This substitution of automated systems for manual detection reduces the difficulty of measuring and detecting traffic patterns in segmented networks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If granular segmentation is implemented to restrict unauthorized communications, then network security is enhanced, but the device complexity for configuring and enforcing policies increases

Engineering Contradiction:
Improvenetwork securityVSAvoidpolicy configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the network segmentation system to self-configure by automatically generating firewall rules and security policies based on metadata about workloads and network requirements. The system uses compiler technology to translate high-level security declarations into enforceable policies without requiring manual configuration, reducing complexity while maintaining granular security control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameters of policy management by using metadata-driven approaches and declarative security policies instead of traditional detailed rule configuration. This parameter change allows the system to maintain granular segmentation with reduced complexity by focusing on what security should achieve rather than how to configure each individual rule.

Inventive Principle:
Principle #35Parameter changes

4Ease of operation

If automated policy generation is used to reduce firewall rule management complexity, then ease of operation is improved, but the extent of automation required increases system complexity

Engineering Contradiction:
Improvefirewall rule management easeVSAvoidautomation system complexity
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The patent uses copying by creating standardized templates and patterns for security policies that can be replicated across different network segments. The compiler-based system generates consistent firewall rules by copying and adapting proven security patterns, reducing both the complexity of automation and the effort required for operation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9787639B1Granular segmentation using events
Publication Date: 2017.10.10 GRYPHO5 LLC
  • US9787639B1 patent drawing
  • US9787639B1 patent drawing
  • US9787639B1 patent drawing

AI summary

Methods and systems for granular segmentation of data networks are provided herein. Exemplary methods include: receiving from a metadata source event metadata associated with a workload; identifying a workload type using the event metadata; determining a high-level declarative security policy using the workload type; launching a compiler to generate a low-level firewall rule set using the high-level declarative policy and the event metadata; and configuring by a plurality of enforcement points a respective network switch of a plurality of network switches to process packets in accordance with the low-level firewall ruleset, the network switches being collectively communicatively coupled to a plurality of workloads, such that network communications between a first group of workloads of the plurality of workloads and the workload are not permitted, and between a second group of workloads of the plurality of workloads and the workload are permitted.