Network Segmentation Feedback for Infrastructure Traffic Alignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Inconsistencies between managed segmentation policies and underlying network infrastructure lead to complexity in network configuration and potential security risks, as network traffic allowed by the policy may be blocked by infrastructure, and changes in infrastructure configuration can inadvertently allow undesired traffic.

Innovation Solution

A computing device identifies discrepancies between a segmentation policy and network infrastructure configuration by using infrastructure feedback, allowing for corrective actions such as notifications, policy modifications, or infrastructure adjustments to align policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the segmentation policy allows network traffic between workloads, then communication between workloads is enabled, but the traffic may be blocked by the network infrastructure (e.g., cloud firewall rules)

Engineering Contradiction:
Improvenetwork traffic communicationVSAvoidtraffic flow consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements feedback by collecting infrastructure feedback (network flow data, policy information) from network infrastructure devices and using it to identify discrepancies between the segmentation policy and actual infrastructure configuration. This feedback loop enables continuous monitoring and alignment of policy with infrastructure state.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The policy management server acts as an intermediary between the segmentation policy configuration and the network infrastructure. It receives infrastructure feedback, identifies discrepancies, and coordinates corrective actions to align the infrastructure configuration with the intended segmentation policy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the network infrastructure configuration is changed to block undesirable traffic, then security is improved, but traffic that should be blocked may inadvertently become allowed

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidconfiguration management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system continuously monitors infrastructure configuration changes and compares them against the segmentation policy. When discrepancies are detected (e.g., infrastructure changes that inadvertently allow undesirable traffic), the system generates notifications and can trigger automated corrective actions to restore security compliance.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary validation by identifying potential discrepancies between segmentation policy and infrastructure configuration before they can cause security issues. By proactively detecting misalignments, the system prevents security gaps from occurring in the first place.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If manual configuration of segmentation policy and network infrastructure is performed, then flexibility in configuration is achieved, but inconsistencies between policy and infrastructure increase

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidpolicy alignment information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system maintains policy alignment information by continuously collecting infrastructure feedback and comparing it with the segmentation policy. This automated feedback mechanism eliminates the information loss that occurs with manual configuration, ensuring that policy and infrastructure remain synchronized without reducing configuration flexibility.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250227039A1Segmentation Using Infrastructure Policy Feedback
Publication Date: 2025.07.10 ILLUMIO INC
  • US20250227039A1 patent drawing
  • US20250227039A1 patent drawing
  • US20250227039A1 patent drawing

AI summary

A computing device (e.g., a policy management server) obtains a segmentation policy that includes a set of rules for controlling network traffic between workloads. The computing device also receives infrastructure feedback regarding configuration of third-party network infrastructure. The computing device uses the infrastructure feedback to identify a discrepancy between the segmentation policy and the configuration of the third-party network infrastructure and triggers a corrective action in response. The corrective action may include providing a notification or suggestive remedy for the discrepancy to the user or automatically remedying the discrepancy.