Microsegmentation Policy Override via Two-Factor Auth

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions face challenges in effectively implementing microsegmentation, especially in serverless computing environments where users do not control the platform, and require complex manual processes that are time-consuming and costly, with legacy approaches failing to provide adequate security and flexibility for temporary overrides.

Innovation Solution

The implementation of machine learning techniques to automate microsegmentation by generating network communication models, using software identity-based technology to create and manage policies, and enabling temporary policy overrides through two-factor authentication for authorized exceptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual microsegmentation rules are created to secure network communications, then security is improved, but deployment time and complexity increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated policy generation by having the network infrastructure itself provide the necessary segmentation rules. The patent describes how the system automatically discovers network topology, identifies communication patterns, and generates microsegmentation policies without requiring manual intervention, thus achieving both security and time efficiency

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary policy generation and validation before actual deployment. The system pre-configures security policies based on observed network behavior and validates them against security requirements before enforcement, reducing on-site deployment time while maintaining security effectiveness

Inventive Principle:
Principle #10Preliminary action

2Reliability

If strict microsegmentation policies are enforced to prevent unauthorized access, then security is improved, but operational flexibility deteriorates

Engineering Contradiction:
Improvesecurity enforcementVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic policy adjustment capabilities that allow the system to adapt security rules based on operational needs. The system can temporarily relax policies for authorized maintenance activities while maintaining strict security during normal operations, achieving both security enforcement and operational flexibility through time-based and context-based policy variations

Inventive Principle:
Principle #15Dynamics

3Difficulty of detecting and measuring

If comprehensive network monitoring is implemented to detect unauthorized communications, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveunauthorized communication detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent describes a monitoring system that performs multiple functions simultaneously: it discovers network topology, identifies communication patterns, detects unauthorized communications, and generates security policies all through a single integrated platform. This multi-functional approach reduces overall system complexity while maintaining comprehensive detection capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20220201041A1Administrative policy override in microsegmentation
Publication Date: 2022.06.23 ZSCALER INC
  • US20220201041A1 patent drawing
  • US20220201041A1 patent drawing
  • US20220201041A1 patent drawing

AI summary

Systems and methods include responsive to monitoring network communications of a network, generating a network communication model that labels the network communications, and generating policies based on the network communication model, wherein the policies specify which applications are authorized to communicate with one another, providing corresponding policies to a plurality systems in the network, wherein each system utilizes the corresponding policies to allow or block communications; responsive to one or more unauthorized communications being needed, performing two-factor authorization to determine if an exception is acceptable; and responsive to the two-factor authorization, providing temporary policies for the exception to allow the one or more unauthorized communications for a period of time.