Policy Tracing Engine for Microsegmented Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In microsegmented networks, tracking and tracing changes in security policies across multiple resources is challenging due to the lack of linkage between administrator-configured policies, dynamic event-induced changes, and their impact on traffic access, making it difficult to determine the cause of policy actions such as allowing or denying traffic.
Innovation Solution
A computer-implemented method and system utilizing a policy tracing engine that monitors events, assigns unique identifiers to intent-based and event-based changes, and generates a traceability report to link changes to security policies, providing a complete traceability of policy actions and their sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If microsegmentation is implemented to control access between resources in a granular way, then network security is improved, but the complexity of tracking and tracing policy changes increases
Solution Approach 1:
The patent introduces a policy tracing engine as an intermediary component that sits between the security policy management system and the microsegmented resources. This engine automatically traces and records policy changes, their causes (administrator actions or dynamic events), and their effects on traffic flow. By delegating the complex tracing task to this specialized intermediary component, the system maintains high security through granular control while avoiding the complexity burden on administrators who would otherwise need to manually track numerous policy changes across multiple resources.
2Adaptability or versatility
If dynamic events are monitored to automatically recompute security policies, then adaptability is improved, but the difficulty of determining policy change sources increases
Solution Approach 1:
The patent implements a feedback mechanism where the policy tracing engine continuously monitors dynamic events (such as IP address changes, role changes, or access permission changes) and automatically traces them back to their sources. When a dynamic event occurs, the engine records the event details, identifies the cause, and updates the policy change trail. This feedback loop enables the system to adapt automatically to changing conditions while maintaining clear visibility into the sources of policy changes, as each change is logged with its originating event or administrator action.
3Measurement precision
If comprehensive policy tracing is implemented to track all changes, then measurement precision is improved, but the loss of time for processing and storing trace information increases
Solution Approach 1:
The patent applies preliminary action by having the policy tracing engine continuously monitor and pre-record policy changes and their causes as they occur, rather than analyzing them retrospectively. The engine maintains a ready-to-query trace database that is continuously updated with policy change information, including the type of change (administrator-initiated or dynamic event), the specific event details, and the resulting policy actions. This preliminary tracking eliminates the need for time-consuming retrospective analysis when security audits or investigations are needed, as all trace information is already captured and organized.
Data Source
AI summary
A computer-implemented method and a system provide a complete traceability of changes incurred in a security policy corresponding to a resource. A policy tracing engine (PTE) monitors and determines events of interest occurring at the resource. The PTE determines administrator-initiated intent-based changes and dynamic event-based changes incurred in the security policy and assigns a unique policy identifier (UPI) to the security policy. The UPI is a combination of unique identifiers assigned to the intent-based change and the event-based change. The PTE recomputes and stores the security policy and the UP in a policy database. The PTE receives network access information including the UPI from the corresponding resource deployed with the security policy. The PTE generates a traceability report that provides a complete traceability of each policy action performed in a networked environment to a source of each change incurred in the security policy as identified by the UPI.


