Identity-Based Network Traffic Filtering via IAM Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional monitoring approaches in computer networks overwhelm related tools and fail to efficiently filter application-specific traffic, relying solely on network and transport layer parameters, which leads to inefficient resource utilization and reduced security.

Innovation Solution

Implement identity-based application-level filtering by deriving context information from Identity and Access Management (IAM) infrastructure to dynamically adjust filtering levels based on user behavior, geographic location, and environmental factors, generating a filtering score to prioritize relevant traffic monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional monitoring approaches (SPAN, mirror ports, TAPs) are used to capture all network traffic, then comprehensive traffic monitoring is achieved, but the monitoring tools become overwhelmed and resource utilization deteriorates

Engineering Contradiction:
Improvetraffic monitoring comprehensivenessVSAvoidmonitoring tool efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments network traffic into different categories based on application identity and sensitivity levels. Instead of treating all traffic uniformly, the system divides traffic into segments that require different monitoring intensities, allowing monitoring tools to focus resources on high-priority traffic while reducing overhead on low-priority traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different monitoring qualities to different traffic segments. High-sensitivity traffic receives comprehensive monitoring with detailed inspection, while low-sensitivity traffic receives minimal monitoring. This local differentiation of quality allows the system to maintain comprehensive monitoring capability where needed while preserving overall tool efficiency.

Inventive Principle:
Principle #3Local quality

2Productivity

If separate network tools attempt to capture application-specific traffic using only network and transport layer parameters, then application-level filtering is attempted, but filtering accuracy deteriorates due to inability to identify application identity

Engineering Contradiction:
Improvefiltering efficiencyVSAvoidapplication identification accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent adds a new dimension to traffic filtering by introducing application identity information derived from IAM infrastructure. Instead of relying solely on traditional network layer parameters (source/destination IP, ports, protocols), the system incorporates application-level identity attributes, creating a multi-dimensional filtering approach that significantly improves application identification accuracy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces an intermediary component that bridges network traffic monitoring and IAM infrastructure. This intermediary derives application identity information from IAM and translates it into filtering criteria that network monitoring tools can use, enabling accurate application-level filtering without requiring the monitoring tools to directly interpret IAM data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If all network traffic is monitored with equal detail, then complete security coverage is achieved, but compute resources and bandwidth are wasted on non-critical traffic

Engineering Contradiction:
Improvesecurity coverageVSAvoidcompute resource utilization
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements dynamic monitoring intensity adjustment based on traffic sensitivity classification. The system continuously adapts monitoring resources allocation by adjusting the depth and breadth of inspection based on the sensitivity level of each traffic flow, ensuring optimal security coverage while minimizing resource consumption on low-priority traffic.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of monitoring intensity from a fixed value to a variable that depends on traffic sensitivity. By modifying monitoring parameters (such as inspection depth, packet sampling rate, and analysis complexity) based on sensitivity classification, the system achieves complete security coverage for critical traffic while reducing resource usage for non-critical traffic.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10148619B1Identity-based application-level filtering of network traffic
Publication Date: 2018.12.04 EMC IP HLDG CO LLC
  • US10148619B1 patent drawing
  • US10148619B1 patent drawing

AI summary

A processing device in one embodiment comprises a processor coupled to a memory and is configured to derive one or more items of context information arising from a given application session within a network, and determine a level of sensitivity to be attributed to the given application session by analyzing one or more factors against the one or more items of context information. The processing device is further configured to generate a filtering score for the given application session based on the determined level of sensitivity, wherein the filtering score indicates a level of relevance attributed to the given application session with respect to a task of monitoring traffic within the network, and output the filtering score to one or more components associated with the network.