ML Zero-Trust Policy Generation for Fine-Grained App Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise networks face challenges in configuring zero-trust policies due to the increased complexity and risk associated with applications moving to the cloud, leading to expanded attack surfaces from wildcard access rules, which are time-consuming and lack fine-grained control.
Innovation Solution
Utilizing machine learning to analyze user-to-application traffic and automatically generate zero-trust policies, reducing onboarding time from months to over a month by identifying app-segments and user-groups, and continuously refining policies based on monitoring and verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual policy configuration is used for zero-trust access, then security control precision can be improved, but configuration time and complexity increase significantly
Solution Approach 1:
The system performs self-service by automatically analyzing network traffic patterns and generating zero-trust policies without requiring manual configuration. The machine learning model autonomously processes traffic data, identifies access patterns, and creates policy recommendations, eliminating the time-consuming manual policy creation process while maintaining high precision through data-driven insights.
Solution Approach 2:
The patent replaces the mechanical manual configuration process with an automated machine learning system. Instead of security personnel manually analyzing traffic and creating policies, the system uses ML algorithms to automatically process traffic data and generate policy recommendations, significantly reducing configuration time while maintaining or improving precision through consistent, data-driven decision-making.
2Ease of operation
If wildcard rules are used for application access, then ease of configuration is improved, but attack surface increases
Solution Approach 1:
The system applies local quality by generating specific, targeted policies for different user groups and applications based on analyzed traffic patterns. Instead of applying uniform wildcard rules across all access scenarios, the machine learning model creates customized policies that match actual usage patterns, allowing precise control over who accesses what, thereby reducing the attack surface while maintaining ease of configuration through automation.
Solution Approach 2:
The patent implements partial action by creating selective access policies rather than comprehensive wildcard rules. The system analyzes traffic to identify only the necessary access relationships that exist in practice, creating policies for specific user-application pairs rather than granting broad access. This partial policy coverage reduces the attack surface by limiting access to only what is actually needed based on observed usage patterns.
3Measurement precision
If fine-grained access control is implemented, then security precision is improved, but policy management complexity increases
Solution Approach 1:
The system performs self-service by automatically generating fine-grained policies based on traffic analysis without requiring manual management of each individual policy. The machine learning model autonomously creates, updates, and refines policies based on observed patterns, eliminating the complexity of manual fine-grained policy management while maintaining high precision through continuous data-driven optimization.
Solution Approach 2:
The patent applies preliminary action by pre-analyzing traffic patterns and pre-generating policy recommendations before deployment. The system processes historical traffic data to identify access patterns and creates policy frameworks in advance, reducing the complexity of ongoing policy management by establishing a data-driven foundation that guides subsequent policy decisions and simplifies iterative refinement.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods include obtaining log data for a plurality of users (102) of an enterprise where the log data relates to usage of a plurality of applications (402, 404) by the plurality of users (102); determining i) app-segments that are groupings of application (402, 404) of the plurality of applications (402, 404) and ii) user-groups that are groupings of users (102) of the plurality of users (102); and providing access policy of the plurality of applications based on the user-groups and the app-segments. The steps can further include monitoring the access policy over time based on ongoing log data, manual verification of the access policy, and incidents where users are prevented from accessing any application (402, 404); and adjusting the determined based on the monitoring.