Network Security Policy Verification via Virtual Traffic Simulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Verifying compliance with security policies across complex networks is challenging due to the need for vendor-dependent configuration awareness and the lack of analytical basis, often resulting in a 'hit or miss' process, especially in networks with multiple communication paths and diverse device configurations.
Innovation Solution
A method and system utilizing a security policy database to generate test traffic that simulates message propagation across a network model, identifying inconsistencies and providing diagnostic tools to determine device configuration issues, and revealing actual security policies when unknown, thereby ensuring compliance with intended security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual security policy verification is performed by security analysts reviewing configuration settings, then the process can identify obvious security loopholes, but the verification becomes a hit or miss process with minimal analytical basis and is extremely time-consuming in complex networks
Solution Approach 1:
The patent creates a virtual copy of the network environment including virtual network devices, configuration data, and topology. This virtual model allows automated simulation and verification of security policies without manually examining each configuration setting, thereby improving verification accuracy while reducing time consumption.
Solution Approach 2:
The system performs preliminary automated analysis by generating test traffic patterns and simulating message propagation through the virtual network model before actual verification. This preliminary action identifies potential security issues systematically, transforming the hit-or-miss manual process into a comprehensive automated verification that is both accurate and efficient.
2Reliability
If security analysts review all configuration settings to verify security policies, then compliance can be checked, but the complexity increases due to vendor-dependent configuration formats and multiple communication paths
Solution Approach 1:
The patent introduces a virtual network model as an intermediary between the actual network devices and the verification process. This virtual model abstracts away vendor-dependent configuration formats and complex communication paths, allowing standardized automated verification while maintaining reliability by accurately representing the actual network behavior.
Solution Approach 2:
The system transforms the verification approach by changing parameters from manual configuration review to automated simulation. By using virtual configuration data and simulated message propagation, the system maintains comprehensive verification reliability while reducing the operational complexity of analyzing vendor-specific formats and multiple communication paths.
3Measurement precision
If comprehensive test traffic is generated to verify all security policies, then accurate verification is achieved, but the network performance may be degraded due to actual traffic generation
Solution Approach 1:
The patent uses a virtual copy of the network to generate and simulate test traffic instead of sending actual traffic through the production network. This virtual test traffic generation achieves comprehensive security policy verification accuracy while completely avoiding degradation of actual network performance, as all testing occurs in the virtual environment.
Solution Approach 2:
The system segments the verification process into virtual simulation and actual network operations. By isolating test traffic generation to the virtual network model segment, the patent achieves accurate security verification without impacting the productivity and performance of the actual network segment.
Data Source
AI summary
A security policy database identifies the intended security policies within a network, a traffic generator provides test traffic that is configured to test each defined security policy, and a simulator simulates the propagation of this traffic on a model of the network. The model of the network includes the configuration data associated with each device, and thus, if devices are properly configured to enforce the intended security policies, the success/failure of the simulated test traffic will conform to the intended permit/deny policy of each connection. Differences between the simulated message propagation and the intended security policies are reported to the user, and diagnostic tools are provided to facilitate identification of the device configuration data that accounts for the observed difference. Additionally, if a network's current security policy is unknown, test traffic is generated to reveal the actual policy in effect, to construct a baseline intended security policy.


