Packet Sentry Internal Network Security via Directory Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for enterprises are inadequate in addressing internal intrusions and unauthorized access, as they primarily focus on perimeter protection and do not understand the internal data flows or directory-centric views within the enterprise, leading to vulnerabilities in internal security.

Innovation Solution

The Packet Sentry system uses directory service information to correlate data streams with users and enforce network policies transparently, conducting flow vector analysis and behavioral monitoring to identify and restrict abnormal access patterns, while integrating directory services for policy enforcement and group relationship analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If perimeter-based security solutions (firewalls, IPS, anti-virus gateways) are used to protect the enterprise, then external attack protection is improved, but internal security monitoring and unauthorized access detection capability deteriorates

Engineering Contradiction:
Improveexternal attack protectionVSAvoidinternal security monitoring capability
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the security function by introducing separate internal monitoring components (flow monitoring, vector analysis, behavioral analysis) that operate independently from perimeter defenses. This allows simultaneous protection against external attacks and detection of internal threats through dedicated internal visibility mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary monitoring layer that sits within the network to observe data flows, user behaviors, and directory service interactions. This intermediary component provides internal security visibility without interfering with external perimeter defense mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If current security products are used to protect the perimeter, then perimeter security is improved, but understanding of internal data flows and directory-centric enterprise view deteriorates

Engineering Contradiction:
Improveperimeter securityVSAvoidinternal data flow information
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent implements a multi-functional monitoring system that simultaneously provides perimeter security, internal flow monitoring, user behavior analysis, and directory service correlation. This universal approach allows a single system to address both external and internal security needs without losing visibility into internal data flows.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent incorporates feedback mechanisms that continuously monitor internal data flows, user behaviors, and directory service interactions to update security policies and detection rules. This feedback loop ensures ongoing improvement of internal security understanding while maintaining perimeter protection.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If traditional security solutions are implemented, then perimeter protection is strengthened, but adaptability to internal security requirements and fluid enterprise network structure deteriorates

Engineering Contradiction:
Improveperimeter protectionVSAvoidinternal security adaptability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security policies that automatically adapt to changing internal conditions, user behaviors, and network topology. The system continuously learns from monitored data flows and directory service changes to update internal security rules, providing adaptability to fluid enterprise network structures while maintaining stable perimeter protection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes security parameters dynamically based on monitored conditions, such as adjusting access controls, monitoring priorities, and detection thresholds according to real-time internal network state and user behavior patterns. This enables adaptability to internal security requirements without compromising perimeter defense.

Inventive Principle:
Principle #35Parameter changes

4Difficulty of detecting and measuring

If directory service integration is added to provide transparent authentication and policy enforcement, then internal security monitoring is improved, but system complexity increases

Engineering Contradiction:
Improveinternal security monitoringVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions (flow monitoring, vector analysis, behavioral analysis, directory service integration, policy enforcement) into a unified system. This consolidation reduces overall complexity by eliminating redundant components and creating integrated workflows, while maintaining comprehensive internal security monitoring capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements self-service mechanisms where the system automatically monitors itself, analyzes its own data flows, and adjusts security policies without requiring complex external configuration. This self-service approach simplifies operation and reduces the complexity burden on administrators while maintaining robust internal security monitoring.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8166554B2Secure enterprise network
Publication Date: 2012.04.24 VMWARE INC
  • US8166554B2 patent drawing
  • US8166554B2 patent drawing
  • US8166554B2 patent drawing

AI summary

What is proposed is a method of implementing a security system (Packet Sentry) addressing the internal security problem of enterprises having a generalized approach for inferential determination and enforcement of network policy with directory service based group correlation with transparent authentication of the connected customer and the policy enforcement inside the network. The security system enables the network to analyze and enforce policy using any bit or bits in a stream or a packet, conduct Flow Vector analysis on the data traffic, provide Application Monitoring, Normalization and user authentication validation. The system enables the network to implement Group relationship Analysis and correlation using combination of Network inferences and Directory service data resulting in generation of Group norms using statistically significant relationships. These will provide a more secure enterprise environment where data security levels can be enforced and the usage monitored effectively in the infrastructure.