Host Threat Policy Enforcement via Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Threat remediation systems are ineffective in monitoring and containing endpoint host threats that move laterally within a network, as they are limited to detecting threats at the perimeter and fail to enforce policies across the entire network, allowing threats to gain access and privileges in unprotected segments.

Innovation Solution

A policy enforcer platform that identifies specific host threats through network addresses, determines associated network elements and control systems, and enforces threat policy actions by creating a policy enforcement group to block and monitor the threats across the network, even when the threats change network addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security controls are placed only at the network perimeter, then the system is simpler to implement, but threats can bypass controls when they laterally move to different network segments

Engineering Contradiction:
Improvethreat containment effectivenessVSAvoidsecurity control architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is divided into multiple segments with distributed security controls at each segment boundary. Each segment has its own policy enforcement group that can independently detect and contain threats, preventing lateral movement while maintaining overall system security through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A central threat intelligence platform acts as an intermediary that collects threat information from multiple sources, correlates data across network segments, and distributes enriched threat intelligence to policy enforcement groups throughout the network, enabling coordinated response without direct peer-to-peer communication between segments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system tracks threats using static network addresses, then the implementation is simpler, but threats can change addresses to evade detection and enforcement

Engineering Contradiction:
Improvethreat tracking accuracyVSAvoidaddress mapping infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system transitions from tracking threats using static network addresses to using dynamic, context-aware identifiers that adapt to address changes. Policy enforcement groups monitor multiple address parameters and maintain threat context regardless of which specific address the threat uses at any given time, enabling continuous tracking despite address rotation.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The policy enforcement group implements a universal threat identification mechanism that works across multiple network segments and address types. A single threat identification system can track threats regardless of their current network location or address assignment, providing multi-functional capability that replaces multiple segment-specific tracking systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If real-time threat monitoring is implemented across the entire network, then threat detection capability improves, but the computational resources and system complexity increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The network monitoring function is segmented into distributed policy enforcement groups at each network segment that perform local threat detection and filtering. Only relevant threat information is forwarded to the central platform, reducing overall computational load while maintaining comprehensive monitoring coverage through hierarchical processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements selective monitoring that focuses computational resources on high-risk activities and threat-relevant traffic patterns rather than analyzing all network traffic uniformly. Policy enforcement groups apply intelligence-based filtering to process only the portion of traffic that poses actual security risks, reducing unnecessary computational expenditure.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11979415B2Enforcing threat policy actions based on network addresses of host threats
Publication Date: 2024.05.07 JUNIPER NETWORKS INC
  • US11979415B2 patent drawing
  • US11979415B2 patent drawing
  • US11979415B2 patent drawing

AI summary

A device receives information identifying a specific host threat to a network, where the information includes a list of network addresses associated with the specific host threat. The device identifies network elements, of the network, associated with the specific host threat to the network, and determines a network control system associated with the identified network elements. The device determines a policy enforcement group of network elements, of the identified network elements, that maps to the list of network addresses associated with the specific host threat, where the network control system is associated with the policy enforcement group of network elements. The device determines a threat policy action to enforce for the specific host threat, and causes, via the network control system, the threat policy action to be enforced by the policy enforcement group of network elements.