Microsegmentation Policy Enforcement Using Application Fingerprints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security technologies struggle with complex and time-consuming microsegmentation, leading to increased risk in cloud and data centers due to excessive access pathways, difficulty in crafting precise access rules, and limited visibility into application identities, making it challenging to prevent unauthorized communications.
Innovation Solution
A system utilizing local security agents on source and destination systems to validate connections through a two-stage process, applying machine learning to generate policies without a backend system, and enforcing policies based on application fingerprints to distinguish permitted from prohibited applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If legacy virtual firewalls are used for network segmentation, then network security can be improved, but cost and complexity increase significantly
Solution Approach 1:
The patent replaces legacy virtual firewalls with a software-based microsegmentation system that uses application fingerprints and distributed security agents. This substitution eliminates the need for complex hardware or virtual firewall infrastructure while achieving comparable or superior security through software-defined policies enforced at the application layer.
Solution Approach 2:
The patent implements microsegmentation by dividing the network into fine-grained segments based on application identities rather than traditional network zones. Each application or service is assigned a unique fingerprint, and access control policies are enforced at the application level, creating secure micro-segments without requiring complex network infrastructure.
2Measurement precision
If manual crafting of precise access rules is performed, then access control precision can be improved, but time consumption increases
Solution Approach 1:
The patent enables the system to automatically generate and enforce access control policies by analyzing application fingerprints and communication patterns. Security agents autonomously collect data about application interactions, and the system automatically translates this into precise access rules without requiring manual intervention, thereby achieving high precision while reducing time consumption.
Solution Approach 2:
The patent implements continuous feedback loops where security agents monitor actual application communications and use this information to dynamically generate and update access control policies. This feedback mechanism allows the system to learn from real-world usage patterns and automatically refine its security rules, achieving precision through data-driven decision-making rather than manual rule crafting.
3Reliability
If traditional network security technologies are used, then network access control can be maintained, but visibility into application identities is limited
Solution Approach 1:
The patent assigns unique visual identifiers (fingerprints) to each application or service, analogous to color coding. These fingerprints provide distinct, easily distinguishable identifiers that enable clear visibility into application identities. The fingerprint mechanism transforms abstract network traffic into visually distinguishable streams that can be easily monitored, identified, and controlled.
Solution Approach 2:
The patent introduces security agents as intermediary components that sit between applications and the network infrastructure. These agents collect detailed information about application identities and communications, acting as mediators that bridge the gap between traditional network security and application-level visibility. The security agents aggregate and present application identity information in a format that is easily actionable for security control.
4Reliability
If fine-grained rules are created to divide network into subnetworks, then microsegmentation can be achieved, but number of rules increases
Solution Approach 1:
The patent changes the fundamental parameter for identifying network entities from IP addresses and ports to application fingerprints. This parameter change enables fine-grained microsegmentation at the application level without requiring a proportional increase in rules. The fingerprint-based approach consolidates multiple IP/port combinations into single application identities, reducing the number of rules while maintaining fine-grained control.
Solution Approach 2:
The patent creates a universal fingerprinting mechanism that can identify and control any application or service regardless of its implementation details. This universal approach allows a single fingerprint to represent multiple network configurations, protocols, or versions of the same application, thereby reducing the total number of rules needed while maintaining comprehensive microsegmentation capability.
Data Source
AI summary
Techniques are disclosed for enforcing application-centric microsegmentation policies in a network using machine learning. A trained machine learning model classifies network communication flows between hosts and applications to generate labeled flows. Based on these classifications, a microsegmentation policy is automatically generated that is independent of underlying network topology and optimized for performance, accuracy, or interpretability. A host in the network receives the microsegmentation policy and applies it locally to flows associated with the host. Enforcement of the policy includes allowing, blocking, quarantining, or redirecting flows according to the labels. The approach enables granular east-west traffic controls, dynamic adaptation to changing flow conditions, and automatic updates based on retrained models. Additional features include hierarchical policy structures, contextual metadata for flow classification, audit logging, and user-facing visualization of microsegments. The disclosed methods improve workload security by providing scalable, data-driven, and automatically generated microsegmentation policies.


