Granular Network Segmentation via Metadata-Driven Firewall Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems, particularly firewalls, face challenges in managing large sets of rules and effectively segmenting data networks to prevent lateral movement of attackers within internal networks, leading to breaches and data theft.
Innovation Solution
The implementation of granular segmentation of data networks through the use of metadata-driven methods, where event metadata is used to identify workload types, generate declarative security policies, and configure network switches to enforce low-level firewall rules, thereby controlling communications between workloads.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall rule management is used to control network traffic, then network security can be maintained, but the complexity of managing large sets of rules increases significantly
Solution Approach 1:
The patent segments the network into multiple isolated segments based on workload types and security requirements. By dividing the network into granular segments and applying firewall rules at the segment level rather than managing a single large rule set, the system reduces management complexity while maintaining security. Each segment enforces its own security policies independently.
Solution Approach 2:
The patent introduces an intermediary system that automatically generates and manages firewall rules based on metadata about workloads and network traffic patterns. This intermediary layer translates high-level security requirements into specific firewall rules, reducing the complexity of direct rule management while ensuring consistent security enforcement.
2Reliability
If network segmentation is implemented to prevent lateral movement of attackers, then security against data breaches is improved, but the difficulty of detecting and measuring traffic patterns increases
Solution Approach 1:
The patent implements feedback mechanisms where the system continuously monitors network traffic patterns within segmented networks and automatically adjusts firewall rules based on detected anomalies. The system uses metadata from traffic flows to identify patterns and responds by modifying segmentation policies, creating a closed-loop system that improves detection capability while maintaining security.
Solution Approach 2:
The patent replaces manual traffic pattern analysis with automated metadata-driven systems that use compiler technology to generate and enforce security policies. This substitution of automated systems for manual detection reduces the difficulty of measuring and detecting traffic patterns in segmented networks.
3Reliability
If granular segmentation is implemented to restrict unauthorized communications, then network security is enhanced, but the device complexity for configuring and enforcing policies increases
Solution Approach 1:
The patent enables the network segmentation system to self-configure by automatically generating firewall rules and security policies based on metadata about workloads and network requirements. The system uses compiler technology to translate high-level security declarations into enforceable policies without requiring manual configuration, reducing complexity while maintaining granular security control.
Solution Approach 2:
The patent changes the parameters of policy management by using metadata-driven approaches and declarative security policies instead of traditional detailed rule configuration. This parameter change allows the system to maintain granular segmentation with reduced complexity by focusing on what security should achieve rather than how to configure each individual rule.
4Ease of operation
If automated policy generation is used to reduce firewall rule management complexity, then ease of operation is improved, but the extent of automation required increases system complexity
Solution Approach 1:
The patent uses copying by creating standardized templates and patterns for security policies that can be replicated across different network segments. The compiler-based system generates consistent firewall rules by copying and adapting proven security patterns, reducing both the complexity of automation and the effort required for operation.
Data Source
AI summary
Methods and systems for granular segmentation of data networks are provided herein. Exemplary methods include: receiving from a metadata source event metadata associated with a workload; identifying a workload type using the event metadata; determining a high-level declarative security policy using the workload type; launching a compiler to generate a low-level firewall rule set using the high-level declarative policy and the event metadata; and configuring by a plurality of enforcement points a respective network switch of a plurality of network switches to process packets in accordance with the low-level firewall ruleset, the network switches being collectively communicatively coupled to a plurality of workloads, such that network communications between a first group of workloads of the plurality of workloads and the workload are not permitted, and between a second group of workloads of the plurality of workloads and the workload are permitted.


