Network Security Policy Graph Overlay for Packet Flow Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security products use complex data structures like red-black trees or compiled versions of security policies, which complicate analysis and increase lookup times, making it difficult to create efficient models of network device security policies for network traffic testing.
Innovation Solution
A method is provided to parse and normalize data from network devices, creating a graphical model that overlays security policies as an abstraction on a network topology graph, allowing for the evaluation of packet flow and integration of security policies with network topology, enabling holistic evaluation across multi-vendor ecosystems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If complex data structures like red-black trees or compiled security policies are used, then lookup times are improved, but analysis and scrutiny become difficult and device complexity increases
Solution Approach 1:
The patent creates a digital twin - a virtual copy of the network device that includes a graphical representation of security policies. This copy allows for easy analysis and visualization without affecting the performance of the actual device. The graphical model serves as an analyzable replica that maintains the essential security policy information in a human-readable format.
Solution Approach 2:
The patent introduces an intermediary graphical representation layer between the complex internal data structures and the user/analyst. This graphical model acts as a mediator that translates complex red-black tree structures into intuitive visual formats, enabling analysis without requiring direct interaction with the complex underlying data structures.
2Loss of time
If complex data structures like red-black trees are used, then lookup times are improved, but ease of manufacture and modeling becomes difficult
Solution Approach 1:
Instead of directly modeling complex red-black tree structures, the patent creates a simplified graphical copy that represents security policies in an intuitive format. This graphical model can be easily constructed and manipulated without dealing with the complexity of binary search tree implementations, making the modeling process much more accessible.
Solution Approach 2:
The patent segments the security policy representation into discrete graphical elements that can be independently created and combined. Rather than building a monolithic complex data structure, the system divides security policies into visual components that can be manufactured and assembled more easily.
3Loss of information
If graphical models overlaying security policies on network topology are created, then visualization and analysis of packet flow is improved, but computational overhead increases
Solution Approach 1:
The patent performs preliminary actions by pre-processing security policies into graphical representations that can be quickly queried. Instead of computing complex data structure traversals during runtime, the system prepares visual models in advance that enable faster analysis of packet flow and security policy interactions.
Solution Approach 2:
The graphical model serves as a lightweight copy that can be used for analysis without requiring the computational resources needed for complex data structure operations. This visual representation enables policy visibility and packet flow analysis with significantly reduced computational overhead compared to manipulating the actual security policy data structures.
Data Source
AI summary
Techniques and architecture are described for abstracting a real physical twin network wherein security policies are mapped as an overlay on a graphical representation of the network topology. The techniques include receiving, at a computing device, a first security policy) for a first network device. The computing device processes the first security policy to generate a plurality of first access control entries. The computing device creates first graph nodes corresponding to the first access control entries. Based at least in part on a processing order of the first security policy on the first network device, the computing device links the first graph nodes into a graph. The computing device displays the graph on a display, wherein the graph is displayed as an overlay on a network topology graph that includes the first network device.


