Network Segmentation Feedback for Infrastructure Traffic Alignment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Inconsistencies between managed segmentation policies and underlying network infrastructure lead to complexity in network configuration and potential security risks, as network traffic allowed by the policy may be blocked by infrastructure, and changes in infrastructure configuration can inadvertently allow undesired traffic.
Innovation Solution
A computing device identifies discrepancies between a segmentation policy and network infrastructure configuration by using infrastructure feedback, allowing for corrective actions such as notifications, policy modifications, or infrastructure adjustments to align policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the segmentation policy allows network traffic between workloads, then communication between workloads is enabled, but the traffic may be blocked by the network infrastructure (e.g., cloud firewall rules)
Solution Approach 1:
The system implements feedback by collecting infrastructure feedback (network flow data, policy information) from network infrastructure devices and using it to identify discrepancies between the segmentation policy and actual infrastructure configuration. This feedback loop enables continuous monitoring and alignment of policy with infrastructure state.
Solution Approach 2:
The policy management server acts as an intermediary between the segmentation policy configuration and the network infrastructure. It receives infrastructure feedback, identifies discrepancies, and coordinates corrective actions to align the infrastructure configuration with the intended segmentation policy.
2Reliability
If the network infrastructure configuration is changed to block undesirable traffic, then security is improved, but traffic that should be blocked may inadvertently become allowed
Solution Approach 1:
The system continuously monitors infrastructure configuration changes and compares them against the segmentation policy. When discrepancies are detected (e.g., infrastructure changes that inadvertently allow undesirable traffic), the system generates notifications and can trigger automated corrective actions to restore security compliance.
Solution Approach 2:
The system performs preliminary validation by identifying potential discrepancies between segmentation policy and infrastructure configuration before they can cause security issues. By proactively detecting misalignments, the system prevents security gaps from occurring in the first place.
3Adaptability or versatility
If manual configuration of segmentation policy and network infrastructure is performed, then flexibility in configuration is achieved, but inconsistencies between policy and infrastructure increase
Solution Approach 1:
The system maintains policy alignment information by continuously collecting infrastructure feedback and comparing it with the segmentation policy. This automated feedback mechanism eliminates the information loss that occurs with manual configuration, ensuring that policy and infrastructure remain synchronized without reducing configuration flexibility.
Data Source
AI summary
A computing device (e.g., a policy management server) obtains a segmentation policy that includes a set of rules for controlling network traffic between workloads. The computing device also receives infrastructure feedback regarding configuration of third-party network infrastructure. The computing device uses the infrastructure feedback to identify a discrepancy between the segmentation policy and the configuration of the third-party network infrastructure and triggers a corrective action in response. The corrective action may include providing a notification or suggestive remedy for the discrepancy to the user or automatically remedying the discrepancy.


