Network Microsegmentation Policy Optimization for Cyber Resilience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for optimizing network microsegmentation policies fail to effectively balance cyberattack risks, accessibility to network resources, and resource limitations within a network environment, making it challenging to determine an optimal security policy for maximum cyber resilience.

Innovation Solution

A method involving the use of matrices to define a model that includes an attack matrix, a mission matrix, and a policy rule matrix, with objectives and constraints to form an optimization problem, which determines candidate security policies that maximize accessibility and minimize cyberattack risks while adhering to resource limitations and mission availability requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network microsegmentation policy is optimized to reduce cyberattack risks, then security resilience is improved, but accessibility to network resources deteriorates

Engineering Contradiction:
Improvecyber resilienceVSAvoidaccessibility to network resources
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies segmentation by dividing the network into micro-segments and creating granular security policies for each segment. The optimization model evaluates multiple candidate policies that segment attack paths while preserving legitimate traffic flows, thereby reducing cyberattack risks without significantly impacting accessibility to network resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes parameters by optimizing security policy rules based on multiple objectives including attack risk reduction and mission availability maintenance. The system adjusts policy parameters (allow/deny rules) dynamically to achieve the optimal balance between security resilience and resource accessibility through mathematical optimization.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If security hardening rules are applied to reduce network vulnerability, then cyberattack risks are reduced, but mission-critical service availability deteriorates

Engineering Contradiction:
Improvecyberattack risksVSAvoidmission availability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent applies parameter changes by optimizing security policy rules through a multi-objective mathematical model that simultaneously considers attack risk reduction and mission availability maintenance. The system adjusts policy parameters to achieve the optimal balance between hardening security and maintaining critical service availability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements feedback mechanisms by evaluating candidate security policies against multiple objectives and constraints, then selecting the optimal policy based on the evaluation results. The system provides feedback on the trade-offs between security hardening and service availability, allowing for iterative optimization of security policies.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If optimization model includes multiple objectives and constraints, then policy optimality is improved, but computational complexity deteriorates

Engineering Contradiction:
Improvepolicy optimalityVSAvoidcomputational complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by breaking down the complex optimization problem into manageable components: defining separate objective functions for different security goals, establishing distinct constraints for various policy requirements, and evaluating candidate policies through systematic analysis of attack paths and traffic flows.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses copying by creating multiple candidate security policies and evaluating them against the optimization model. Instead of directly solving the complex optimization problem, the system generates candidate solutions and selects the optimal one, reducing computational complexity while maintaining policy optimality.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240356961A1Optimizing networks microsegmentation policy for cyber resilience
Publication Date: 2024.10.24 THE MITRE CORPORATION
  • US20240356961A1 patent drawing
  • US20240356961A1 patent drawing
  • US20240356961A1 patent drawing

AI summary

Described herein is a system and method for improving cyber resilience for determining an optimal security policy for a network. The system uses an objective function to balance cyberattack risks, accessibility to network resources, resource limitations, minimum mission availability requirements within a network environment, or a combination thereof. The objective function comprises objectives (one or more variables that enhance accessibility to network resources and reduce cyberattack risks) and constraints (one or more variables that characterize resource limitations or minimum mission availability requirements within a network environment). The optimal security policy is selected by solving one or more optimization problems. The optimization problem may be solved by determining candidate security policies that meet the constraints and selecting among candidate security policies having the highest score for a given objective function.