Location-Based Application Segments for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of cloud-based applications and the extension of enterprise networks beyond traditional perimeters have resulted in heightened security risks, including data breaches on unsecured devices and vulnerabilities in accessing sensitive applications.
Innovation Solution
The implementation of a cloud-based system that generates location-based application segments by leveraging transactional data and location information to adjust application segmentation factor thresholds, thereby reducing the attack surface and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional perimeter-based security is used, then security for on-premises resources is maintained, but security for cloud-based applications and mobile users deteriorates
Solution Approach 1:
The patent applies segmentation by dividing applications into location-based segments (e.g., office locations, remote locations, mobile locations) and user groups into location-based categories. This allows security policies to be applied at the application level rather than network level, enabling differentiated security controls for different application types and locations while maintaining adaptability to various access scenarios.
Solution Approach 2:
The patent transitions from traditional network perimeter-based security to application-level security by adding a new dimension of classification based on application location and type. This dimensional shift enables security controls to operate independently of network topology, addressing both on-premises and cloud-based applications uniformly while maintaining adaptability to diverse access patterns.
2Device complexity
If application segmentation is performed without location data, then segmentation process is simpler, but security effectiveness deteriorates
Solution Approach 1:
The patent performs preliminary classification of applications into segments based on location data before applying security policies. By pre-categorizing applications into location-based segments (office, remote, mobile) and pre-defining access rules for each segment, the system simplifies the overall security management process while enhancing effectiveness through location-aware segmentation.
Solution Approach 2:
The patent changes the parameter used for application classification from traditional network-based criteria to location-based criteria. This parameter change enables more effective security segmentation by considering where applications are accessed from rather than where they are hosted, thereby improving security effectiveness without significantly increasing process complexity.
3Reliability
If location-based application segments are generated, then security against lateral movement is improved, but data processing requirements increase
Solution Approach 1:
The patent extracts location information from transactional data and uses it to classify applications into segments. By extracting only the necessary location metadata rather than processing complete transactional records, the system reduces data processing volume while maintaining the ability to generate effective location-based application segments for security control.
Solution Approach 2:
The patent applies partial action by processing only the location-related portions of transactional data rather than analyzing all data fields. This selective processing approach reduces the quantity of data that needs to be processed while still providing sufficient information to generate accurate location-based segments for security purposes.
4Reliability
If application access is restricted based on location segments, then security is enhanced, but user accessibility may deteriorate
Solution Approach 1:
The patent applies local quality by implementing differentiated access policies for different application segments based on their location characteristics. Each application segment receives customized access controls appropriate to its deployment environment (office, remote, or mobile), allowing security to be enhanced where needed while maintaining ease of access for legitimate users through location-appropriate policies.
Data Source
AI summary
Systems and methods for generating location-based application segments include obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users; obtaining location data associated with the plurality of applications; and generating one or more application segments based on the transactional data and the location data. In various embodiments, the location data can be leveraged to alter various application segmentation factor thresholds for adapting the likelihood of applications to be grouped together.


