Network Security Device Automated Asset Definition Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security devices face challenges in keeping pace with the dynamic changes in asset definitions and attributes, leading to delays in updating security policies, which can hinder effective network protection, especially as the number of assets increases, and manual processes become burdensome.
Innovation Solution
Implementing a system where network security devices automatically learn and update asset definitions and attributes in real-time from external systems like VM systems and SIEM systems, without disrupting ongoing security policies, by receiving updated information and dynamically updating the run-time configuration within the kernel of the network security operating system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual processes are used to add and update asset definitions and attributes, then network administrators can maintain control over security policies, but the process becomes burdensome and delays occur in updating definitions as the number of assets increases
Solution Approach 1:
The network security device automatically learns and updates asset definitions and attributes by receiving information from external systems without requiring manual administrator intervention. The device performs self-updates of its run-time representation of security policy rules, eliminating the burden of manual processes while maintaining current asset information.
Solution Approach 2:
External systems pre-define and maintain asset definitions and attributes before the network security device needs them. The external systems perform the work of asset definition in advance, and the network security device simply receives and applies these pre-prepared definitions, eliminating delays in updating asset information.
2Reliability
If asset definitions are updated in real-time from external systems, then network security devices can maintain up-to-date information and effectively enforce security policies, but the system complexity increases
Solution Approach 1:
External systems act as intermediaries that maintain and manage asset definitions and attributes. These external systems serve as the source of truth for asset information, and the network security device receives updates from them through standardized interfaces, simplifying the overall architecture while ensuring accurate and current asset information.
Solution Approach 2:
The system separates the asset definition function from the security policy enforcement function. External systems are responsible for defining and maintaining asset information, while the network security device focuses on receiving these definitions and applying them to security policies. This segmentation allows each component to specialize and reduces the complexity burden on any single system.
3Productivity
If automated learning from external systems is implemented, then the administrative burden is reduced and real-time updates are achieved, but the device must integrate with multiple external systems increasing operational complexity
Solution Approach 1:
The network security device is designed with universal capabilities to receive asset definition information from multiple types of external systems including virtualization platforms, asset management systems, and security information event monitoring systems. By implementing a unified interface that can work with various external sources, the device achieves real-time updates without requiring separate integration mechanisms for each system type.
Data Source
AI summary
Systems and methods for automated learning of externally defined network assets by a network security device are provided. According to one embodiment, updated information for a network asset associated with a private network is received by a network security device from an external asset management device associated with the private network. The updated information includes a change in a definition or an attribute of the network asset. The existence of a current definition and attribute information for the network asset is determined by the network security device. The current definition and attribute information is dynamically updated based on the updated information by the network security system within a run-time representation of security policy rules within a kernel of a network security operating system without disrupting on-going application of one or more security policy rules defined for the network asset to network traffic directed to or originated by the network asset.


