Network Security Policy Generation via Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing host-based network security technologies, such as firewalls, require tedious and error-prone manual processes for generating, modifying, and deleting security policies, especially during changes in network topology or device connections, which can be time-consuming and prone to errors.

Innovation Solution

The use of machine learning to generate network communication policies based on existing network communications, without the need for labeled training data, allowing for the validation of communications between applications over a network by creating human-readable rules that balance permissiveness and restrictiveness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual processes are used to generate, modify, and delete security policies, then policy accuracy can be controlled, but the process becomes tedious, time-consuming, and error-prone

Engineering Contradiction:
Improvepolicy generation accuracyVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically generates security policies by analyzing network traffic patterns and application behaviors without requiring manual intervention. The machine learning model self-adjusts and updates policies based on observed network conditions, eliminating the need for manual policy creation while maintaining accuracy through data-driven decision-making

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual mechanical processes of policy creation are replaced with automated machine learning algorithms that process network data and generate policies computationally. The system substitutes human operators with AI models that can rapidly analyze network traffic and produce accurate security policies without time consumption

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual processes are used to generate, modify, and delete security policies, then policy accuracy can be controlled, but the process becomes prone to errors

Engineering Contradiction:
Improvepolicy generation accuracyVSAvoidoperational error rate
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically generates security policies by analyzing network traffic patterns and application behaviors without requiring manual intervention. The machine learning model self-adjusts and updates policies based on observed network conditions, eliminating the need for manual policy creation while maintaining accuracy through data-driven decision-making

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual mechanical processes of policy creation are replaced with automated machine learning algorithms that process network data and generate policies computationally. The system substitutes human operators with AI models that can rapidly analyze network traffic and produce accurate security policies without time consumption

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If existing host-based firewalls are used to monitor connections, then directional access control is achieved, but the system complexity increases during network topology changes

Engineering Contradiction:
Improveaccess control capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The machine learning model serves multiple functions: it analyzes network traffic, identifies application behaviors, generates security policies, and adapts to topology changes simultaneously. This multi-functional approach consolidates what would otherwise require multiple separate systems into a single unified platform, reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adapts to changing network topologies and application behaviors through continuous machine learning. Rather than requiring manual reconfiguration when network conditions change, the model automatically updates its understanding of legitimate traffic patterns and adjusts policies accordingly, reducing operational complexity

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11522890B2Network application security policy generation
Publication Date: 2022.12.06 ZSCALER INC
  • US11522890B2 patent drawing
  • US11522890B2 patent drawing
  • US11522890B2 patent drawing

AI summary

Embodiments of the present invention generate network communication policies by applying machine learning to existing network communications, and without using information that labels such communications as healthy or unhealthy. The resulting policies may be used to validate communication between applications (or services) over a network.