Automated Individual Access Policies Through Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security models struggle to implement granular access control policies for individual users and devices due to the complexity of managing thousands of remote users and mobile devices, leading to over-privileged access and increased risk of infection spread, as they transition from a 'castle and moat' to a Zero Trust Access architecture.

Innovation Solution

A system and method for automatically identifying and recording user or host entities, monitoring network communications, correlating network addresses with entity names, and proposing access control policies through network traffic analysis, behavior analysis, and machine learning, with human review or automatic implementation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual firewall rule creation for each user is implemented, then granular access control is achieved, but the complexity and time required for policy creation becomes impossible

Engineering Contradiction:
Improveaccess control granularityVSAvoidpolicy management complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically discovering network traffic patterns and generating access control policies without human intervention. The machine learning model autonomously analyzes communication patterns between users, devices, and applications to create granular policies, eliminating the need for manual rule creation while maintaining high precision in access control granularity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of creating firewall rules with an automated machine learning system. The ML model substitutes human administrators in the policy creation process, using algorithms to analyze network traffic and generate policies automatically, thereby reducing complexity while maintaining or improving access control precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If group level access policies are implemented, then policy creation becomes manageable, but over-privileged access occurs reducing security effectiveness

Engineering Contradiction:
Improvepolicy creation easeVSAvoidsecurity control effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies local quality by creating individualized access policies for each user based on their specific network traffic patterns, rather than applying uniform group-level policies. The machine learning model analyzes each user's communications separately and generates tailored policies that grant only the specific access each user needs, eliminating over-privileged access while keeping policy management feasible through automation.

Inventive Principle:
Principle #3Local quality

3Productivity

If default allow model is used, then network operations are simple, but security risks increase due to over-privileged access

Engineering Contradiction:
Improvenetwork operation efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system inverts the traditional default allow model by implementing a learned allow approach. Instead of allowing all traffic by default and manually creating deny rules, the machine learning model starts with no permissions and automatically generates allow policies based on observed legitimate traffic patterns. This inversion maintains security by only permitting what is necessary while preserving network operation efficiency through automated policy generation.

Inventive Principle:
Principle #13The other way round (Inversion)

4Reliability

If Zero Trust Access model is implemented, then security posture is improved, but the complexity of creating individual user policies becomes unmanageable

Engineering Contradiction:
Improvesecurity postureVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies preliminary action by implementing a learning phase during which the machine learning model observes and analyzes network traffic patterns before policies are enforced. This preliminary observation period allows the system to build an understanding of legitimate communications, and only after this learning phase are the access control policies applied. This approach simplifies implementation by separating the complex analysis phase from the enforcement phase, making Zero Trust manageable.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250220053A1System and method for creating access control policies for individual users, user groups, network host or network host groups through network traffic analysis
Publication Date: 2025.07.03 ERICOM SOFTWARE
  • US20250220053A1 patent drawing
  • US20250220053A1 patent drawing

AI summary

A method and system for automatically creating access control policies for a network, including: (a) automatically identifying and recording user or host entities that attach to the network; (b) monitoring allowed network communications from the user or host entities; (c) correlating network address information from the allowed network communications with names of the user or host entities; and (d) proposing a respective access control policy for each of the user or host entities based on information gleaned during a learning process.