Host Profile Enforcement for Granular Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewalls do not adequately protect devices communicating through them by failing to determine client device-specific information and enforce policies based on this information, such as the presence of up-to-date security software.

Innovation Solution

Implementing policy enforcement using host profile information (HIP), which involves receiving and analyzing host information profile reports from client devices to enforce security policies based on device-specific information, including software installations and configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall rules are used to filter network traffic, then basic network security is maintained, but the firewall cannot enforce policies based on device-specific information such as security software presence

Engineering Contradiction:
Improvenetwork securityVSAvoidpolicy enforcement capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a host information profile (HIP) agent as an intermediary component that collects device-specific information and transmits it to the firewall. This HIP agent acts as a mediator between the client device and the firewall, enabling the firewall to access detailed host information without directly implementing the collection mechanism. The HIP agent gathers data about security software, operating system, and other device characteristics, then forwards this information to the firewall for policy enforcement decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the firewall collects and analyzes detailed host information from client devices, then more granular policy enforcement is achieved, but the complexity of the firewall system increases

Engineering Contradiction:
Improvepolicy enforcement granularityVSAvoidfirewall system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the system into distinct functional segments: the HIP agent on client devices responsible for information collection, the communication channel for data transmission, and the firewall for policy enforcement. This segmentation allows each component to specialize in its specific function, reducing the overall complexity burden on the firewall while enabling detailed policy enforcement through the distributed HIP architecture.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the firewall enforces policies based on host profile information, then only secure devices can access sensitive resources, but additional processing and communication overhead is introduced

Engineering Contradiction:
Improvedevice security verificationVSAvoidpolicy enforcement processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The HIP agent continuously collects and maintains host information profile data before firewall policy enforcement is needed. By pre-gathering device information about security software, operating system, and other characteristics, the system avoids the need for time-consuming data collection during actual policy enforcement moments. The HIP data is readily available when the firewall needs to make access decisions, reducing processing delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12316679B2Policy enforcement using host profile
Publication Date: 2025.05.27 PALO ALTO NETWORKS INC
  • US12316679B2 patent drawing
  • US12316679B2 patent drawing
  • US12316679B2 patent drawing

AI summary

Embodiments of the present application relate to a method for policy enforcement, a system for policy enforcement, and a computer program product for policy enforcement. A method for policy enforcement is provided. The method includes receiving a host information profile report from a client device, and enforcing a security policy for network access based on the host information profile report. The host information profile report includes device profile information associated with the client device.