Microsegmentation Policy Override via Two-Factor Auth
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions face challenges in effectively implementing microsegmentation, especially in serverless computing environments where users do not control the platform, and require complex manual processes that are time-consuming and costly, with legacy approaches failing to provide adequate security and flexibility for temporary overrides.
Innovation Solution
The implementation of machine learning techniques to automate microsegmentation by generating network communication models, using software identity-based technology to create and manage policies, and enabling temporary policy overrides through two-factor authentication for authorized exceptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual microsegmentation rules are created to secure network communications, then security is improved, but deployment time and complexity increase significantly
Solution Approach 1:
The system enables automated policy generation by having the network infrastructure itself provide the necessary segmentation rules. The patent describes how the system automatically discovers network topology, identifies communication patterns, and generates microsegmentation policies without requiring manual intervention, thus achieving both security and time efficiency
Solution Approach 2:
The patent implements preliminary policy generation and validation before actual deployment. The system pre-configures security policies based on observed network behavior and validates them against security requirements before enforcement, reducing on-site deployment time while maintaining security effectiveness
2Reliability
If strict microsegmentation policies are enforced to prevent unauthorized access, then security is improved, but operational flexibility deteriorates
Solution Approach 1:
The patent implements dynamic policy adjustment capabilities that allow the system to adapt security rules based on operational needs. The system can temporarily relax policies for authorized maintenance activities while maintaining strict security during normal operations, achieving both security enforcement and operational flexibility through time-based and context-based policy variations
3Difficulty of detecting and measuring
If comprehensive network monitoring is implemented to detect unauthorized communications, then security detection capability is improved, but system complexity increases
Solution Approach 1:
The patent describes a monitoring system that performs multiple functions simultaneously: it discovers network topology, identifies communication patterns, detects unauthorized communications, and generates security policies all through a single integrated platform. This multi-functional approach reduces overall system complexity while maintaining comprehensive detection capabilities
Data Source
AI summary
Systems and methods include responsive to monitoring network communications of a network, generating a network communication model that labels the network communications, and generating policies based on the network communication model, wherein the policies specify which applications are authorized to communicate with one another, providing corresponding policies to a plurality systems in the network, wherein each system utilizes the corresponding policies to allow or block communications; responsive to one or more unauthorized communications being needed, performing two-factor authorization to determine if an exception is acceptable; and responsive to the two-factor authorization, providing temporary policies for the exception to allow the one or more unauthorized communications for a period of time.


