Packet Sentry Internal Network Security via Directory Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security solutions for enterprises are inadequate in addressing internal intrusions and unauthorized access, as they primarily focus on perimeter protection and do not understand the internal data flows or directory-centric views within the enterprise, leading to vulnerabilities in internal security.
Innovation Solution
The Packet Sentry system uses directory service information to correlate data streams with users and enforce network policies transparently, conducting flow vector analysis and behavioral monitoring to identify and restrict abnormal access patterns, while integrating directory services for policy enforcement and group relationship analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If perimeter-based security solutions (firewalls, IPS, anti-virus gateways) are used to protect the enterprise, then external attack protection is improved, but internal security monitoring and unauthorized access detection capability deteriorates
Solution Approach 1:
The patent segments the security function by introducing separate internal monitoring components (flow monitoring, vector analysis, behavioral analysis) that operate independently from perimeter defenses. This allows simultaneous protection against external attacks and detection of internal threats through dedicated internal visibility mechanisms.
Solution Approach 2:
The patent introduces an intermediary monitoring layer that sits within the network to observe data flows, user behaviors, and directory service interactions. This intermediary component provides internal security visibility without interfering with external perimeter defense mechanisms.
2Object-affected harmful factors
If current security products are used to protect the perimeter, then perimeter security is improved, but understanding of internal data flows and directory-centric enterprise view deteriorates
Solution Approach 1:
The patent implements a multi-functional monitoring system that simultaneously provides perimeter security, internal flow monitoring, user behavior analysis, and directory service correlation. This universal approach allows a single system to address both external and internal security needs without losing visibility into internal data flows.
Solution Approach 2:
The patent incorporates feedback mechanisms that continuously monitor internal data flows, user behaviors, and directory service interactions to update security policies and detection rules. This feedback loop ensures ongoing improvement of internal security understanding while maintaining perimeter protection.
3Object-affected harmful factors
If traditional security solutions are implemented, then perimeter protection is strengthened, but adaptability to internal security requirements and fluid enterprise network structure deteriorates
Solution Approach 1:
The patent implements dynamic security policies that automatically adapt to changing internal conditions, user behaviors, and network topology. The system continuously learns from monitored data flows and directory service changes to update internal security rules, providing adaptability to fluid enterprise network structures while maintaining stable perimeter protection.
Solution Approach 2:
The patent changes security parameters dynamically based on monitored conditions, such as adjusting access controls, monitoring priorities, and detection thresholds according to real-time internal network state and user behavior patterns. This enables adaptability to internal security requirements without compromising perimeter defense.
4Difficulty of detecting and measuring
If directory service integration is added to provide transparent authentication and policy enforcement, then internal security monitoring is improved, but system complexity increases
Solution Approach 1:
The patent merges multiple security functions (flow monitoring, vector analysis, behavioral analysis, directory service integration, policy enforcement) into a unified system. This consolidation reduces overall complexity by eliminating redundant components and creating integrated workflows, while maintaining comprehensive internal security monitoring capabilities.
Solution Approach 2:
The patent implements self-service mechanisms where the system automatically monitors itself, analyzes its own data flows, and adjusts security policies without requiring complex external configuration. This self-service approach simplifies operation and reduces the complexity burden on administrators while maintaining robust internal security monitoring.
Data Source
AI summary
What is proposed is a method of implementing a security system (Packet Sentry) addressing the internal security problem of enterprises having a generalized approach for inferential determination and enforcement of network policy with directory service based group correlation with transparent authentication of the connected customer and the policy enforcement inside the network. The security system enables the network to analyze and enforce policy using any bit or bits in a stream or a packet, conduct Flow Vector analysis on the data traffic, provide Application Monitoring, Normalization and user authentication validation. The system enables the network to implement Group relationship Analysis and correlation using combination of Network inferences and Directory service data resulting in generation of Group norms using statistically significant relationships. These will provide a more secure enterprise environment where data security levels can be enforced and the usage monitored effectively in the infrastructure.


