OSI Layer 4+ Security Policy Enforcement via Authentication Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitoring systems are limited in their ability to enforce security policies at higher layers of the OSI model, particularly at the Session and Presentation layers, where application security risks are more prevalent, and are not effectively mapped against specific users, leading to diminished protection capabilities.

Innovation Solution

A method and system that monitors authentication events and communication flows to define, validate, and enforce security policies at layer 4 and higher, using authentication information to model user behavior and detect policy violations across the network, allowing for user-based policy enforcement and alert generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network monitoring systems are used to enforce security policies, then network security management is simplified through centralized policy definition, but the systems are limited to lower OSI layers and cannot effectively enforce policies at Session and Presentation layers where application security risks are more prevalent

Engineering Contradiction:
Improvenetwork security protection capabilityVSAvoidpolicy enforcement layer coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends security policy enforcement from traditional network layer (layer 3) and transport layer (layer 4) to higher application layers including Session (layer 5) and Presentation (layer 6). This dimensional expansion allows the system to monitor and enforce policies based on application-specific parameters such as authentication events, user identities, and application protocols, thereby resolving the contradiction between maintaining simplified centralized management and achieving broader layer coverage for enhanced security reliability

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The policy-based management system is enhanced to perform multiple functions across different OSI layers. It now simultaneously handles traditional network-level policy enforcement and application-layer security policy enforcement through unified policy definitions. The system can define single policies that apply across multiple layers and protocols, making the management system more versatile while maintaining the simplicity of centralized policy definition

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If policies are applied to network entities individually by setting operating parameters separately, then precise control over specific devices is achieved, but configuration complexity increases significantly across large networks

Engineering Contradiction:
Improvepolicy control precisionVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements policy templates that can be universally applied across multiple network entities simultaneously. A single policy definition can be instantiated across numerous devices, protocols, and layers through parameterization. This allows administrators to maintain precise control over specific devices while avoiding the complexity of individual configuration, as the same policy framework can manage everything from network switches to application servers with consistent rules

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses parameterized policy definitions where specific policy instances are created by substituting parameters into template definitions. This allows the same policy structure to be applied across different contexts with minimal modification. Administrators can control precision through parameter selection rather than through complex structural changes, thereby maintaining control precision while reducing configuration complexity

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If security policies are limited to lower OSI layers (data link and network layers), then implementation is simpler and more widely compatible, but protection capability against application-layer threats is diminished

Engineering Contradiction:
Improvepolicy implementation easeVSAvoidapplication security protection
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent extends policy enforcement capabilities upward through the OSI model to include Session layer (layer 5) and Presentation layer (layer 6) monitoring. By adding this dimensional extension to the traditional network-layer-focused approach, the system can now inspect and enforce policies based on application-specific information such as authentication events, user identities, and application protocols while maintaining compatibility with existing network infrastructure

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent segments policy enforcement into distinct functional components that can operate at different OSI layers independently. The system divides security monitoring into network-level policy enforcement and application-level policy enforcement, allowing each segment to be optimized for its specific layer while contributing to overall security. This segmentation enables gradual adoption and maintains simplicity at lower layers while adding enhanced protection at application layers

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8146160B2Method and system for authentication event security policy generation
Publication Date: 2012.03.27 ARBOR NETWORKS INC
  • US8146160B2 patent drawing
  • US8146160B2 patent drawing
  • US8146160B2 patent drawing

AI summary

A method and system allows for the deployment of security policies into the higher layers of the OSI model. Specifically, it allows for the establishment of security policies at layer 4 and higher, by monitoring authentication flows and using these flows as the basis for establishing security policies which then can be used as a basis for assessing the operation of the network.