Intent-Based Network Security Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security policies often become unorganized due to frequent rule modifications, making it difficult for administrators to track the original intent and changes, which can compromise network security and resource efficiency, especially during attacks.

Innovation Solution

A network device capable of determining the intent of a security policy and mapping security rules to apply them correctly, using natural language processing and machine learning to parse security rules and identify intent, thereby facilitating organized management and efficient tracking of changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security rules are frequently modified to adapt to changing network threats, then the adaptability and security response capability are improved, but the organization and traceability of the security policy deteriorate

Engineering Contradiction:
Improvesecurity response capabilityVSAvoidpolicy organization
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system performs preliminary actions by automatically generating documentation and mapping security rules to business intents before administrators need to review or audit the policy. This proactive approach maintains organization despite frequent changes, as the system continuously updates the policy representation without requiring manual reorganization efforts.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If manual tracking of security policy changes is implemented, then the traceability of policy intent is improved, but the administrative overhead and time consumption increase

Engineering Contradiction:
Improvepolicy intent traceabilityVSAvoidadministrative time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system enables self-service by automatically generating policy documentation, change tracking, and intent mapping without requiring administrator intervention. The system serves itself by continuously analyzing security rule changes and maintaining the policy representation, freeing administrators from manual tracking tasks while preserving complete traceability of policy intent.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive security rule documentation is maintained, then the accuracy of policy interpretation is improved, but the processing overhead and storage requirements increase

Engineering Contradiction:
Improvepolicy interpretation accuracyVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system extracts and separates the essential business intent from the detailed security rule syntax. By representing policies at the intent level rather than maintaining complete documentation of every rule detail, the system achieves accurate policy interpretation while minimizing processing overhead and storage requirements. Only the critical intent information is retained and processed.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If security policies are made highly specific to address particular threats, then the security precision is improved, but the complexity of policy management increases

Engineering Contradiction:
Improvesecurity precisionVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by maintaining specific, precise security rules where needed while representing them through generalized intent mappings for management purposes. Each security rule retains its specific threat-response characteristics for accurate enforcement, but the intent-based representation allows administrators to manage policies at a higher level of abstraction, reducing overall complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3422663B1Intent-based network security policy modification
Publication Date: 2022.07.13 JUNIPER NETWORKS INC
  • EP3422663B1 patent drawingFigure 1A
  • EP3422663B1 patent drawingFigure 1B
  • EP3422663B1 patent drawingFigure 2

AI summary

A device may receive first information associated with a set of security rules (145). The first information may identify a set of security actions a device is to implement when the set of security rules applies to traffic. The device may determine (135) a manner in which the set of security rules is to apply using the first information. The device may determine whether the manner in which the set of security rules is to apply and an intent of a network security policy or a manner in which a set of previously defined security rules (130) is to apply match to determine whether the set of security rules conflicts with the network security policy or whether the set of security rules and the set of previously defined security rules are related. The device may perform an action (140), such as inserting the security rules into the security policy.