Automated Network Security Rule Generation for Microsegmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions require manual rule definition, becoming less scalable with increasing network resources, and are prone to errors, leading to security vulnerabilities.

Innovation Solution

An automated system that generates enhanced network security rules by analyzing existing security rules, monitoring network traffic, and identifying unused communication paths, thereby reducing data traffic and improving security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual security rule definition is used, then security control is maintained, but scalability deteriorates as network resources increase

Engineering Contradiction:
Improvesecurity controlVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system enables self-service by having the network itself generate security rules through automated analysis of traffic patterns and topology maps, eliminating the need for manual engineer intervention while maintaining security control and scaling with network growth

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual rule-definition process with an automated computer-based system that uses algorithms to analyze network traffic data, generate topology maps, and create security rules, thereby improving scalability while maintaining security effectiveness

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual security rule definition is used, then security policy can be implemented, but time consumption increases significantly

Engineering Contradiction:
Improvesecurity policy implementationVSAvoidrule generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by continuously monitoring network traffic and pre-generating topology maps before security rules need to be updated, allowing rapid rule generation without time-consuming manual analysis when security policy changes are required

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent substitutes manual time-consuming rule creation with automated computational processes that quickly analyze traffic patterns and generate rules, reducing rule generation time from hours to seconds while maintaining policy accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual security rule definition is used, then security rules can be created, but error rate increases due to human factors

Engineering Contradiction:
Improvesecurity rule accuracyVSAvoidhuman error
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces human-based rule creation with automated computer systems that use algorithms to analyze network data, eliminating human errors such as typos, omissions, and misconfigurations while maintaining or improving rule accuracy through systematic analysis

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system incorporates feedback mechanisms by continuously monitoring network traffic and comparing actual usage against generated rules, allowing automatic adjustments and corrections to ensure accuracy while eliminating human error in the rule generation process

Inventive Principle:
Principle #23Feedback

4Stability of the object's composition

If multiple communication paths are maintained for redundancy, then system reliability improves, but security surface area increases

Engineering Contradiction:
Improvecommunication path redundancyVSAvoidsecurity surface area
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The system uses feedback from actual network traffic monitoring to dynamically adjust security rules, automatically closing unused communication paths while maintaining redundancy for actively used paths, thereby reducing security surface area without compromising operational reliability

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements dynamic security rules that automatically adapt to changing network usage patterns, maintaining open communication paths only when traffic is detected and closing them when unused, allowing the security posture to dynamically balance redundancy and security surface area

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3891953B1Automatic generation of security rules for network micro and NANO segmentation
Publication Date: 2025.04.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3891953B1 patent drawingFigure 1
  • EP3891953B1 patent drawingFigure 2
  • EP3891953B1 patent drawingFigure 3

AI summary

Methods, systems, apparatuses, and computer program products are provided for generating a network security rule. Existing security rules may be determined across a network that includes a plurality of network resources, such as computing devices or virtual machines. A map is generated that identifies each of the permitted connections between the resources over the network. In some implementations, the map may include a network topology map. Network traffic data for each of the permitted connections may be gathered or monitored. Based on the existing security rules and the gathered network traffic data, an enhanced security rule may be generated for a particular connection that reduces data traffic over connection, which improves network security by further hardening the available communication paths.