Microsegmented Network Security Policy Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing systems, microsegmentation for security is challenging due to the lack of detailed knowledge about network addresses and ports, which hinders the proper configuration of security policies, especially since intra-system communications within the firewall boundary are not controlled by traditional firewalls.

Innovation Solution

A computer-implemented method generates security policies by creating port service and distribution maps, analyzing traffic logs, and assigning estimated accuracy to recommendations, thereby identifying allowed source and destination IP addresses and ports for microsegmented systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls are used to filter incoming packets, then external network security is improved, but intra-system communications are not controlled and security policies cannot be properly configured

Engineering Contradiction:
Improveexternal network securityVSAvoidintra-system communication control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies segmentation by dividing network security control into two distinct layers: external firewall protection for incoming packets and internal microsegmentation for intra-system communications. This allows traditional firewalls to continue protecting external boundaries while separate security policies control internal traffic between servers, resolving the contradiction between maintaining external security and enabling internal communication control.

Inventive Principle:
Principle #1Segmentation

2Reliability

If microsegmentation is implemented for granular security control, then intra-system security is improved, but the lack of detailed network address and port knowledge hinders proper configuration

Engineering Contradiction:
Improveintra-system securityVSAvoidsecurity policy configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by automatically discovering and mapping network addresses, ports, and service relationships before security policies need to be configured. The system performs preliminary network reconnaissance to build a comprehensive view of intra-system communication patterns, which then serves as the foundation for generating appropriate security policies, thereby reducing configuration complexity while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If security policy recommendations are generated without accuracy metrics, then policy generation speed is improved, but false positives increase and reduce recommendation reliability

Engineering Contradiction:
Improvepolicy generation speedVSAvoidrecommendation accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies feedback by incorporating accuracy metrics and confidence scores into security policy recommendations. The system analyzes traffic logs and port service maps to generate recommendations with associated reliability indicators, allowing administrators to prioritize and validate recommendations based on their accuracy metrics. This feedback mechanism maintains productivity by automating the analysis while improving reliability through transparent accuracy assessment.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11075950B2Generation of security policies for microsegmented computer networks
Publication Date: 2021.07.27 CA TECH INC
  • US11075950B2 patent drawing
  • US11075950B2 patent drawing
  • US11075950B2 patent drawing

AI summary

A computer-implemented method of generating a security policy for a microsegmented computing system is provided. The method includes generating a port service map that indicates inbound packet activity by port for a plurality of network addresses within the microsegmented computing system and a port distribution map that indicates inbound packet activity by port for a plurality of network addresses within the microsegmented computing system, and generating a list of security policy recommendations based on the port service map and/or the port distribution map.