Microsegmentation Policy Enforcement Using Application Fingerprints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies struggle with complex and time-consuming microsegmentation, leading to increased risk in cloud and data centers due to excessive access pathways, difficulty in crafting precise access rules, and limited visibility into application identities, making it challenging to prevent unauthorized communications.

Innovation Solution

A system utilizing local security agents on source and destination systems to validate connections through a two-stage process, applying machine learning to generate policies without a backend system, and enforcing policies based on application fingerprints to distinguish permitted from prohibited applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy virtual firewalls are used for network segmentation, then network security can be improved, but cost and complexity increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces legacy virtual firewalls with a software-based microsegmentation system that uses application fingerprints and distributed security agents. This substitution eliminates the need for complex hardware or virtual firewall infrastructure while achieving comparable or superior security through software-defined policies enforced at the application layer.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements microsegmentation by dividing the network into fine-grained segments based on application identities rather than traditional network zones. Each application or service is assigned a unique fingerprint, and access control policies are enforced at the application level, creating secure micro-segments without requiring complex network infrastructure.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If manual crafting of precise access rules is performed, then access control precision can be improved, but time consumption increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent enables the system to automatically generate and enforce access control policies by analyzing application fingerprints and communication patterns. Security agents autonomously collect data about application interactions, and the system automatically translates this into precise access rules without requiring manual intervention, thereby achieving high precision while reducing time consumption.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements continuous feedback loops where security agents monitor actual application communications and use this information to dynamically generate and update access control policies. This feedback mechanism allows the system to learn from real-world usage patterns and automatically refine its security rules, achieving precision through data-driven decision-making rather than manual rule crafting.

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional network security technologies are used, then network access control can be maintained, but visibility into application identities is limited

Engineering Contradiction:
Improvenetwork access controlVSAvoidvisibility into application identities
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent assigns unique visual identifiers (fingerprints) to each application or service, analogous to color coding. These fingerprints provide distinct, easily distinguishable identifiers that enable clear visibility into application identities. The fingerprint mechanism transforms abstract network traffic into visually distinguishable streams that can be easily monitored, identified, and controlled.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent introduces security agents as intermediary components that sit between applications and the network infrastructure. These agents collect detailed information about application identities and communications, acting as mediators that bridge the gap between traditional network security and application-level visibility. The security agents aggregate and present application identity information in a format that is easily actionable for security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If fine-grained rules are created to divide network into subnetworks, then microsegmentation can be achieved, but number of rules increases

Engineering Contradiction:
ImprovemicrosegmentationVSAvoidnumber of rules
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent changes the fundamental parameter for identifying network entities from IP addresses and ports to application fingerprints. This parameter change enables fine-grained microsegmentation at the application level without requiring a proportional increase in rules. The fingerprint-based approach consolidates multiple IP/port combinations into single application identities, reducing the number of rules while maintaining fine-grained control.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a universal fingerprinting mechanism that can identify and control any application or service regardless of its implementation details. This universal approach allows a single fingerprint to represent multiple network configurations, protocols, or versions of the same application, thereby reducing the total number of rules needed while maintaining comprehensive microsegmentation capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260067336A1Distributed Network Application Security Policy Generation and Enforcement for Microsegmentation
Publication Date: 2026.03.05 ZSCALER INC
  • US20260067336A1 patent drawing
  • US20260067336A1 patent drawing
  • US20260067336A1 patent drawing

AI summary

Techniques are disclosed for enforcing application-centric microsegmentation policies in a network using machine learning. A trained machine learning model classifies network communication flows between hosts and applications to generate labeled flows. Based on these classifications, a microsegmentation policy is automatically generated that is independent of underlying network topology and optimized for performance, accuracy, or interpretability. A host in the network receives the microsegmentation policy and applies it locally to flows associated with the host. Enforcement of the policy includes allowing, blocking, quarantining, or redirecting flows according to the labels. The approach enables granular east-west traffic controls, dynamic adaptation to changing flow conditions, and automatic updates based on retrained models. Additional features include hierarchical policy structures, contextual metadata for flow classification, audit logging, and user-facing visualization of microsegments. The disclosed methods improve workload security by providing scalable, data-driven, and automatically generated microsegmentation policies.