Link Prediction for Network Microsegmentation Policy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures struggle to predict future communications links in complex computing networks, leading to reactive microsegmentation policies that may not effectively address future network traffic patterns.
Innovation Solution
The system collects traffic information, generates a graph model of the network, and uses various node similarity and grouping methods to predict future communications links. This information is then used to develop a proactive microsegmentation policy that balances network resource availability with malicious user restriction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If microsegmentation policy is based only on observed traffic links, then the policy reflects past network activity accurately, but it cannot predict or prepare for future network traffic patterns
Solution Approach 1:
The patent applies preliminary action by using link prediction algorithms to forecast future communication links before they actually occur. The system analyzes historical traffic data, constructs graph models, and predicts potential future connections between computing devices. This allows the microsegmentation policy to be proactively configured in advance, rather than reactively responding to observed traffic only.
2Object-affected harmful factors
If heavy-handed microsegmentation policy is implemented to restrict malicious user activity, then security is improved, but authorized user access to network resources becomes frustrated
Solution Approach 1:
The patent applies local quality by creating fine-grained microsegmentation policies at the level of individual computing devices and specific communication links. Instead of applying uniform restrictive rules across the entire network, the system analyzes traffic patterns device-by-device and creates customized access rules for each node and link. This allows security restrictions to be applied locally where needed while maintaining ease of access in other areas.
Solution Approach 2:
The patent applies dynamics by making the microsegmentation policy adaptive and dynamic rather than static. The system continuously monitors network traffic, updates link predictions based on changing patterns, and adjusts access rules accordingly. This dynamic approach allows the policy to automatically accommodate legitimate user needs while maintaining security, balancing restriction and accessibility in real-time.
3Productivity
If relaxed microsegmentation policy is implemented to allow efficient authorized user access, then network resource availability is improved, but malicious user access is not effectively restricted
Solution Approach 1:
By predicting future links in advance, the system can proactively establish appropriate access rules before malicious activity occurs. This preliminary configuration allows legitimate traffic to flow efficiently while pre-positioning security controls to block potential threats, achieving both high productivity and security.
4Object-affected harmful factors
If perimeter-based security is used to protect network assets, then external access control is achieved, but internal network movement freedom is excessive once breached
Solution Approach 1:
The patent applies segmentation by dividing the network into fine-grained micro-segments at the level of individual computing devices and communication links. This granular segmentation replaces traditional perimeter-based security with layered micro-perimeters throughout the network. When a breach occurs, the segmentation limits lateral movement by containing threats within specific micro-segments, preventing unrestricted access to the entire internal network.
Data Source
AI summary
Described herein are systems and methods for grouping computing devices in a computing network and predicting future communications links between computing devices for the purpose of developing a computing network microsegmentation policy. In one or more examples, the systems and methods described herein can predict future links in a computing network using a plurality of combinations of node similarity, node grouping, and link prediction methods. Each unique combination of methods can be assessed by comparing the predicted links to observed network traffic to determine the quality of the prediction. The quality of prediction can be assessed by generate F1 curves for each combination of methods. The combination with the highest quality prediction can then be selected and tuned (by adjusting a threshold associated with the combination). Once tuned, the selected combination (i.e., model) can then be used generate and/or modify a microsegmentation policy associated with the computing network.


