Network Device Session Analysis for Granular Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional policy enforcement firewalls fail to effectively control access and optimize network efficiency based on application classification during sessions, lacking granular control over user, location, time, role, and targeted destination.

Innovation Solution

A network device analyzes session information to classify applications and enforce policies by mapping session-to-application relationships, incorporating factors like SRC port numbers, SRC IP addresses, and DNS traffic to apply tailored policies for peer-to-peer applications and other classifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional policy enforcement firewalls are used to control user access, then user-based access control is achieved, but application-level control and network efficiency optimization are lost

Engineering Contradiction:
Improveapplication-level controlVSAvoidpolicy enforcement capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments policy enforcement into multiple hierarchical levels: user-based policies, application-based policies, and session-based policies. The system divides the firewall functionality to analyze different packet attributes (source IP, destination IP, port numbers, protocol types) separately and applies corresponding policies at each level, enabling granular application-level control while maintaining operational simplicity through structured policy layers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds application classification as a new dimension to traditional user-based policy enforcement. By introducing application identification based on deep packet inspection and session analysis, the system transforms 2D user-based control into 3D control spanning user, application, and session dimensions, thereby achieving application-level versatility without compromising ease of operation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If user-based policy enforcement is implemented, then access control between user classes is provided, but granular control based on application classification is lost

Engineering Contradiction:
Improvegranular controlVSAvoidpolicy analysis mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-defining application classification rules and policy templates before actual traffic analysis. The system pre-establishes relationships between packet attributes and application types, and pre-configures policy conditions based on application classifications. This allows granular control to be achieved without increasing real-time analysis complexity, as the heavy classification work is done in advance.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If conventional firewalls control access based on user identity, then user class separation is achieved, but network efficiency optimization based on application type is prevented

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidpolicy enforcement mechanism
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms where the firewall continuously monitors traffic patterns, application classifications, and policy violation rates. Based on this feedback, the system dynamically adjusts policy enforcement intensity and optimizes network resource allocation. For example, applications with high productivity value receive preferential treatment while maintaining security, and policy rules are automatically refined based on observed traffic behavior, improving network efficiency without complicating operation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9356964B2Application based policy enforcement
Publication Date: 2016.05.31 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9356964B2 patent drawing
  • US9356964B2 patent drawing
  • US9356964B2 patent drawing

AI summary

One embodiment is directed to a system that comprises a network device, including at least a first port, which is configured to analyze information within one or more messages received during a session initiated by another network device. The system is configured to perform operations including determining a total number of sessions for the first port of the network device and determining whether the total number of sessions for the first port exceeds a threshold value. If the total number of sessions for the first port exceeds the threshold value, an application associated with the first port is classified as a peer-to-peer application. Thereafter, a policy may be enforced based on this classification.