Policy Tracing Engine for Microsegmented Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In microsegmented networks, tracking and tracing changes in security policies across multiple resources is challenging due to the lack of linkage between administrator-configured policies, dynamic event-induced changes, and their impact on traffic access, making it difficult to determine the cause of policy actions such as allowing or denying traffic.

Innovation Solution

A computer-implemented method and system utilizing a policy tracing engine that monitors events, assigns unique identifiers to intent-based and event-based changes, and generates a traceability report to link changes to security policies, providing a complete traceability of policy actions and their sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If microsegmentation is implemented to control access between resources in a granular way, then network security is improved, but the complexity of tracking and tracing policy changes increases

Engineering Contradiction:
Improvenetwork securityVSAvoidpolicy change tracking complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a policy tracing engine as an intermediary component that sits between the security policy management system and the microsegmented resources. This engine automatically traces and records policy changes, their causes (administrator actions or dynamic events), and their effects on traffic flow. By delegating the complex tracing task to this specialized intermediary component, the system maintains high security through granular control while avoiding the complexity burden on administrators who would otherwise need to manually track numerous policy changes across multiple resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If dynamic events are monitored to automatically recompute security policies, then adaptability is improved, but the difficulty of determining policy change sources increases

Engineering Contradiction:
Improvepolicy adaptabilityVSAvoidpolicy change source identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the policy tracing engine continuously monitors dynamic events (such as IP address changes, role changes, or access permission changes) and automatically traces them back to their sources. When a dynamic event occurs, the engine records the event details, identifies the cause, and updates the policy change trail. This feedback loop enables the system to adapt automatically to changing conditions while maintaining clear visibility into the sources of policy changes, as each change is logged with its originating event or administrator action.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive policy tracing is implemented to track all changes, then measurement precision is improved, but the loss of time for processing and storing trace information increases

Engineering Contradiction:
Improvepolicy change tracking precisionVSAvoidtrace processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the policy tracing engine continuously monitor and pre-record policy changes and their causes as they occur, rather than analyzing them retrospectively. The engine maintains a ready-to-query trace database that is continuously updated with policy change information, including the type of change (administrator-initiated or dynamic event), the specific event details, and the resulting policy actions. This preliminary tracking eliminates the need for time-consuming retrospective analysis when security audits or investigations are needed, as all trace information is already captured and organized.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11363068B2Method and system for providing a complete traceability of changes incurred in a security policy
Publication Date: 2022.06.14 COLORTOKENS INC
  • US11363068B2 patent drawing
  • US11363068B2 patent drawing
  • US11363068B2 patent drawing

AI summary

A computer-implemented method and a system provide a complete traceability of changes incurred in a security policy corresponding to a resource. A policy tracing engine (PTE) monitors and determines events of interest occurring at the resource. The PTE determines administrator-initiated intent-based changes and dynamic event-based changes incurred in the security policy and assigns a unique policy identifier (UPI) to the security policy. The UPI is a combination of unique identifiers assigned to the intent-based change and the event-based change. The PTE recomputes and stores the security policy and the UP in a policy database. The PTE receives network access information including the UPI from the corresponding resource deployed with the security policy. The PTE generates a traceability report that provides a complete traceability of each policy action performed in a networked environment to a source of each change incurred in the security policy as identified by the UPI.