Network Device Session Analysis for Granular Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional policy enforcement firewalls fail to effectively control access and optimize network efficiency based on application classification during sessions, lacking granular control over user, location, time, role, and targeted destination.
Innovation Solution
A network device analyzes session information to classify applications and enforce policies by mapping session-to-application relationships, incorporating factors like SRC port numbers, SRC IP addresses, and DNS traffic to apply tailored policies for peer-to-peer applications and other classifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional policy enforcement firewalls are used to control user access, then user-based access control is achieved, but application-level control and network efficiency optimization are lost
Solution Approach 1:
The patent segments policy enforcement into multiple hierarchical levels: user-based policies, application-based policies, and session-based policies. The system divides the firewall functionality to analyze different packet attributes (source IP, destination IP, port numbers, protocol types) separately and applies corresponding policies at each level, enabling granular application-level control while maintaining operational simplicity through structured policy layers.
Solution Approach 2:
The patent adds application classification as a new dimension to traditional user-based policy enforcement. By introducing application identification based on deep packet inspection and session analysis, the system transforms 2D user-based control into 3D control spanning user, application, and session dimensions, thereby achieving application-level versatility without compromising ease of operation.
2Adaptability or versatility
If user-based policy enforcement is implemented, then access control between user classes is provided, but granular control based on application classification is lost
Solution Approach 1:
The patent implements preliminary action by pre-defining application classification rules and policy templates before actual traffic analysis. The system pre-establishes relationships between packet attributes and application types, and pre-configures policy conditions based on application classifications. This allows granular control to be achieved without increasing real-time analysis complexity, as the heavy classification work is done in advance.
3Productivity
If conventional firewalls control access based on user identity, then user class separation is achieved, but network efficiency optimization based on application type is prevented
Solution Approach 1:
The patent implements feedback mechanisms where the firewall continuously monitors traffic patterns, application classifications, and policy violation rates. Based on this feedback, the system dynamically adjusts policy enforcement intensity and optimizes network resource allocation. For example, applications with high productivity value receive preferential treatment while maintaining security, and policy rules are automatically refined based on observed traffic behavior, improving network efficiency without complicating operation.
Data Source
AI summary
One embodiment is directed to a system that comprises a network device, including at least a first port, which is configured to analyze information within one or more messages received during a session initiated by another network device. The system is configured to perform operations including determining a total number of sessions for the first port of the network device and determining whether the total number of sessions for the first port exceeds a threshold value. If the total number of sessions for the first port exceeds the threshold value, an application associated with the first port is classified as a peer-to-peer application. Thereafter, a policy may be enforced based on this classification.


