Network Access Analysis System for Unobserved Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based network environments face challenges in maintaining secure and optimized network access controls, as users often struggle with manually auditing and updating firewall rules, route tables, and other access controls to prevent unauthorized access and ensure least privilege permissions.

Innovation Solution

A network-access analysis (NAA) system that automates the analysis of network access controls by combining static analysis to identify all possible paths in a network configuration and active traffic analysis to sample network traffic. This system identifies unobserved traffic flows and potential security threats, then provides recommendations for proposed changes to network access controls to restrict unnecessary access while ensuring that necessary traffic flows are not blocked.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually audit and update firewall rules and network access controls, then network security can be maintained, but the complexity and time required for managing access controls increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically analyzes network traffic flows and access control configurations to identify and recommend changes to unnecessary rules. The analysis system serves itself by autonomously detecting unobserved traffic flows and generating proposed modifications to firewall rules and network ACLs without requiring manual intervention, thereby maintaining security while reducing management complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic flows and compares them against configured access control rules. By providing feedback on which rules are not matching any observed traffic, the system enables dynamic optimization of access controls, allowing users to maintain high security with simplified rule sets by removing unnecessary restrictions

Inventive Principle:
Principle #23Feedback

2Productivity

If users configure permissive network access controls to ensure application functionality, then service availability is maintained, but network security is compromised due to unnecessary access paths

Engineering Contradiction:
Improveapplication functionalityVSAvoidunauthorized access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system extracts and identifies specific access control rules that do not correspond to any observed network traffic flows. By separating and removing these unnecessary permissive rules from the access control configuration, the system reduces the attack surface and unauthorized access risk while preserving all rules that are actually needed for application functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary analysis of network traffic patterns before finalizing access control configurations. By proactively identifying which access rules are not being used based on observed traffic flows, the system prepares optimized access control settings that maintain necessary functionality while preemptively removing security vulnerabilities from the configuration

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If users manually review and modify every network access control rule, then precise control over traffic flows is achieved, but the time and resources required for maintenance increase significantly

Engineering Contradiction:
Improvetraffic flow control precisionVSAvoidaccess control maintenance time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system replaces manual mechanical review processes with automated computational analysis. The analysis system uses algorithms to automatically compare configured access control rules against observed network traffic flows, identifying which rules are necessary and which can be removed. This substitution of automated analysis for manual review maintains precise control over traffic flows while dramatically reducing the time and resources required for maintenance

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12335149B1Least privilege network access controls advisor
Publication Date: 2025.06.17 AMAZON TECH INC
  • US12335149B1 patent drawing
  • US12335149B1 patent drawing
  • US12335149B1 patent drawing

AI summary

Techniques implemented by a network-access analysis system to analyze network access controls for networks, identify traffic flows that are unobserved and unrequired, and determine proposed changes to the network access controls that restrict access from unobserved traffic flows. The system may analyze the network access controls, and determine whether unrequired traffic flows are allowed to be communicated in the network. For instance, the system may analyze network flow logs and identify observed traffic flows that are required by applications in the network, and also identify unobserved traffic flows that are permitted access to, but are not observed in, the network. The system may propose changes to the network access controls to restrict network access by these unobserved traffic flows. A network administrator can receive recommendations from the system regarding the proposed changes, and determine whether they would like to implement the proposed changes to their network access controls.