Network Policy Group Optimization via Graph Theory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity of network policies due to organizational structure, regulatory requirements, and security threats leads to a significant increase in the number of rules, overwhelming computational and memory resources, causing bottlenecks and degrading network performance.
Innovation Solution
The use of graph theory to model and optimize communications between objects, grouping them into source and destination groups to reduce the number of rules through a generalized group optimization algorithm (G2OA), which translates policies into a simplified tensor and list of 3D vectors, minimizing the storage and processing requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network policies are expanded to cover increasing organizational complexity, regulatory requirements, and security threats, then network security and compliance are improved, but computational and memory resources are overwhelmed causing bottlenecks and degraded network performance
Solution Approach 1:
The patent segments the large network policy into multiple smaller policy sets, each enforced by different network elements. This division reduces the computational and memory burden on individual network elements while maintaining comprehensive security coverage across the entire network through coordinated enforcement of segmented policies.
2Reliability
If the number of network policy rules is increased to address organizational complexity and security threats, then network security coverage is improved, but the size of policies and memory requirements increase
Solution Approach 1:
The patent divides the comprehensive network policy into multiple smaller policy sets that can be distributed across different network elements. This segmentation reduces the policy size stored at each individual element while collectively providing complete security coverage through the coordinated enforcement of all policy sets.
3Reliability
If network policies are expanded with more rules, then security compliance is improved, but computational resources needed to process policies increase
Solution Approach 1:
The patent segments the computationally intensive policy processing task across multiple network elements, with each element enforcing a specific policy set. This distribution reduces the computational resource consumption at each individual element while collectively achieving complete compliance enforcement through coordinated policy execution.
Data Source
AI summary
Disclosed embodiments are related to grouping sets of intercommunicating objects to minimize the number of rules/policies needed to be stored to enforce those rules/policies. Given a set of objects communicating with each other using different services, embodiments group these objects to minimize the total number of final rules that are implemented. This allows an original set of policies to be reduced into a smaller set of policies, which conserves computational resources. Other embodiments may be described and/or claimed.


