Host-Based Network Policy Mechanism for Port-Circumvention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional policy mechanisms in computer networks are statically configured and traffic-based, making them ineffective in limiting or blocking certain types of network behavior, as clients can easily circumvent these limitations by switching to different ports after the initial handshake process, requiring constant monitoring and rule updates.

Innovation Solution

Implementing a host-based network policy mechanism that identifies and limits traffic at the host level, using a processing engine to inspect packets and apply rules based on predetermined patterns and host identifiers, regardless of the port used for subsequent data transfers, thereby addressing the limitations of traditional traffic-based approaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional traffic-based policy mechanisms are used to limit or block certain types of traffic, then specific traffic patterns can be controlled, but clients can easily circumvent these limitations by switching to different ports after the initial handshake process

Engineering Contradiction:
Improvetraffic limitation effectivenessVSAvoidclient ability to circumvent limitations
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from static traffic-based policy mechanisms to dynamic host-based policy mechanisms. The system dynamically identifies hosts through handshake detection and continuously applies policy rules to all subsequent traffic from identified hosts, regardless of port changes. This dynamic approach ensures that policy limitations remain effective even when clients switch ports, as the policy follows the host rather than being tied to specific traffic patterns or ports.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If traditional static policy mechanisms are configured manually to affect specific traffic types, then configuration simplicity is maintained, but constant monitoring and rule updates are required to address new traffic patterns

Engineering Contradiction:
Improvepolicy configuration simplicityVSAvoidtime for constant monitoring and rule updates
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements a self-service mechanism where the network device automatically performs host identification through handshake detection and autonomously applies policy rules to identified hosts. The system self-updates by continuously monitoring for new handshakes and automatically extending policy application to newly identified hosts without requiring administrator intervention. This eliminates the need for constant manual monitoring and rule updates while maintaining policy effectiveness.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If traffic-based policy rules are applied to specific ports, then initial handshake traffic can be limited, but subsequent data transfers on different ports are not addressed

Engineering Contradiction:
Improvetraffic identification accuracyVSAvoidcoverage across different ports
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal host-based policy mechanism that applies to all traffic from identified hosts across all ports. Instead of creating separate rules for each port or traffic pattern, the system identifies hosts through initial handshake detection and then applies the same policy rules universally to all subsequent traffic from those hosts, regardless of which port is used. This multi-functional approach ensures comprehensive coverage while reducing the number of specific rules needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9154583B2Methods and devices for implementing network policy mechanisms
Publication Date: 2015.10.06 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9154583B2 patent drawing
  • US9154583B2 patent drawing
  • US9154583B2 patent drawing

AI summary

Embodiments of the invention provide a network device for implementing a host-based network policy mechanism, having a port for receiving packets wherein each packet identifies a host and a destination, and a processing engine configured to inspect packets received on the port, wherein if at least one of the packets matches a predetermined pattern, a rule regulating packet transmission originating from the host is defined and applied against subsequent packets received on the port.