Automated Individual Access Policies Through Network Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security models struggle to implement granular access control policies for individual users and devices due to the complexity of managing thousands of remote users and mobile devices, leading to over-privileged access and increased risk of infection spread, as they transition from a 'castle and moat' to a Zero Trust Access architecture.
Innovation Solution
A system and method for automatically identifying and recording user or host entities, monitoring network communications, correlating network addresses with entity names, and proposing access control policies through network traffic analysis, behavior analysis, and machine learning, with human review or automatic implementation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If manual firewall rule creation for each user is implemented, then granular access control is achieved, but the complexity and time required for policy creation becomes impossible
Solution Approach 1:
The system performs self-service by automatically discovering network traffic patterns and generating access control policies without human intervention. The machine learning model autonomously analyzes communication patterns between users, devices, and applications to create granular policies, eliminating the need for manual rule creation while maintaining high precision in access control granularity.
Solution Approach 2:
The patent replaces the mechanical manual process of creating firewall rules with an automated machine learning system. The ML model substitutes human administrators in the policy creation process, using algorithms to analyze network traffic and generate policies automatically, thereby reducing complexity while maintaining or improving access control precision.
2Ease of operation
If group level access policies are implemented, then policy creation becomes manageable, but over-privileged access occurs reducing security effectiveness
Solution Approach 1:
The system applies local quality by creating individualized access policies for each user based on their specific network traffic patterns, rather than applying uniform group-level policies. The machine learning model analyzes each user's communications separately and generates tailored policies that grant only the specific access each user needs, eliminating over-privileged access while keeping policy management feasible through automation.
3Productivity
If default allow model is used, then network operations are simple, but security risks increase due to over-privileged access
Solution Approach 1:
The system inverts the traditional default allow model by implementing a learned allow approach. Instead of allowing all traffic by default and manually creating deny rules, the machine learning model starts with no permissions and automatically generates allow policies based on observed legitimate traffic patterns. This inversion maintains security by only permitting what is necessary while preserving network operation efficiency through automated policy generation.
4Reliability
If Zero Trust Access model is implemented, then security posture is improved, but the complexity of creating individual user policies becomes unmanageable
Solution Approach 1:
The system applies preliminary action by implementing a learning phase during which the machine learning model observes and analyzes network traffic patterns before policies are enforced. This preliminary observation period allows the system to build an understanding of legitimate communications, and only after this learning phase are the access control policies applied. This approach simplifies implementation by separating the complex analysis phase from the enforcement phase, making Zero Trust manageable.
Data Source
AI summary
A method and system for automatically creating access control policies for a network, including: (a) automatically identifying and recording user or host entities that attach to the network; (b) monitoring allowed network communications from the user or host entities; (c) correlating network address information from the allowed network communications with names of the user or host entities; and (d) proposing a respective access control policy for each of the user or host entities based on information gleaned during a learning process.

