Logical Multi-Dimensional Label Policy for Server Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional server management policies are difficult to express in a fine-grained, abstract, and natural way due to their reliance on low-level constructs like IP addresses and network interfaces, making it challenging to implement effective administrative domain-wide management policies.
Innovation Solution
A method and system for quarantining a managed server within an administrative domain by modifying its description, updating cached actor-sets, and determining relevant updates to enforce a management policy, which isolates the server if a network attack or vulnerability is detected, using a logical multi-dimensional label-based policy model.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional policies reference physical devices and low-level constructs like IP addresses, then device identification is straightforward, but policy expression becomes difficult and coarse-grained
Solution Approach 1:
The patent introduces a logical dimension layer above the physical device layer. Instead of managing policies solely through physical identifiers (IP addresses, device names), the system adds logical identifiers and abstract policy constructs that operate at a higher level of abstraction. This dimensional addition allows policies to be expressed in terms of logical relationships and functional requirements rather than low-level technical details, resolving the contradiction between ease of policy expression and the inherent complexity of device-level management.
Solution Approach 2:
The patent introduces logical identifiers and abstract policy constructs as intermediaries between the physical device layer and the policy management layer. These intermediaries (logical device names, service identifiers, policy templates) mediate the connection between concrete physical devices and abstract policy requirements, enabling finer-grained and more natural policy expression without directly managing the complexity of physical device identifiers.
2Manufacturing precision
If policies are expressed in low-level constructs, then implementation is direct, but fine-grained control is difficult to achieve
Solution Approach 1:
The patent segments policy management into multiple hierarchical levels: physical device identification, logical device identification, service-level policies, and application-level policies. This segmentation allows each layer to operate at its appropriate level of granularity, with abstract logical constructs handling fine-grained control requirements while physical identifiers provide the foundational layer. The segmented structure enables precise policy control without requiring policymakers to write complex low-level configurations.
Solution Approach 2:
By adding the logical identifier dimension, the system enables fine-grained policy differentiation without increasing the complexity of policy writing. Logical identifiers provide an additional degree of freedom that allows policies to be distinguished and controlled at a finer level (e.g., differentiating between different services or applications on the same device) while maintaining ease of expression through abstract, human-readable constructs.
3Reliability
If server isolation is implemented through physical separation, then security is enhanced, but resource utilization decreases
Solution Approach 1:
The patent applies local quality by implementing isolation policies selectively rather than universally. Instead of physically separating all servers, the system applies isolation measures only to specific servers or services that require enhanced security or compliance. The logical identifier framework enables differentiation of isolation requirements across different servers, allowing critical servers to be isolated while non-critical servers share resources, thus maintaining both security and resource utilization efficiency.
Solution Approach 2:
The patent implements dynamic isolation capabilities where the isolation state of servers can be changed based on security requirements, threat levels, or compliance needs. The logical policy framework allows isolation to be adjusted in real-time without physical reconfiguration - servers can be dynamically isolated or reintegrated into shared resource pools based on current security conditions, optimizing both security and resource utilization adaptively.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A managed server (MS) within an administrative domain is quarantined. The administrative domain includes multiple MSs that use management instructions to configure management modules so that the configured management modules implement an administrative domain- wide management policy that comprises a set of one or more rules. The quarantined MS is isolated from other MSs. A description of the MS is modified to indicate that the MS is quarantined, thereby specifying a description of the quarantined MS. Cached actor-sets are updated to indicate the quarantined MS's changed state, thereby specifying updated actor- sets. A determination is made regarding which updated actor-sets are relevant to an other MS, thereby specifying currently-relevant updated actor-sets. A determination is made regarding whether the currently-relevant updated actor-sets differ from actor-sets previously sent to the other MS. Responsive to determining that the currently-relevant updated actor-sets are identical to the previously-sent actor-sets, no further action is taken.