Network Security Policy Filtering via Routing Topology

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in efficiently distributing relevant cybersecurity threat information to enterprise network endpoints due to limited memory and processing capabilities, especially with rapidly changing routing topologies and limited access control list space, leading to difficulties in ensuring only topologically relevant policies are installed and irrelevant policies are not left on devices.

Innovation Solution

A system where network devices subscribe to a central threat repository, with policies filtered to install only current attack vectors from subnets learned via routing, using publish/subscribe mechanisms to continually refine and update policies based on routing changes, and applying dynamic security policies at the access edge using routing and forwarding information as filter criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If global cybersecurity threat information is distributed to all network endpoints, then network security coverage is improved, but memory and processing burdens at endpoints increase beyond their limited capabilities

Engineering Contradiction:
Improvenetwork security coverageVSAvoidmemory and processing resources at endpoints
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the global cybersecurity threat information into route-specific subsets. Each network device receives only the threat information relevant to its locally learned routes, rather than distributing all global threat data to every endpoint. This segmentation reduces the quantity of information each device must store and process while maintaining comprehensive security coverage across the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by tailoring the security policy information to each network device's specific context. Each device receives threat information filtered by its local routing table, so that device-specific memory and processing resources are utilized efficiently for locally relevant threats only, rather than uniformly distributing identical information to all endpoints.

Inventive Principle:
Principle #3Local quality

2Reliability

If comprehensive security policies are installed on all devices, then security protection is improved, but control over topologically relevant policies becomes difficult due to limited ACL space

Engineering Contradiction:
Improvesecurity protectionVSAvoidACL space management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the topologically relevant portion of global security policies based on each device's local routing information. By using routing tables as filter criteria, the system extracts and installs only those threat-related policies that are relevant to the device's actual network connections, leaving out irrelevant policies and preventing ACL space exhaustion.

Inventive Principle:
Principle #2Taking out (Extraction)

3Speed

If security policies are updated frequently to reflect changing threats, then security responsiveness is improved, but maintaining policy relevance becomes difficult with dynamic routing topologies

Engineering Contradiction:
Improvesecurity responsivenessVSAvoidpolicy relevance
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent establishes a feedback mechanism where network devices report their locally learned routes back to the security system. This feedback loop allows the system to continuously update and refine which threat information is distributed to each device, ensuring that security policies remain relevant to the current network topology while responding quickly to new threats.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent makes the security policy distribution dynamic by linking it to real-time routing information. As network topology changes and devices learn new routes, the set of relevant threat information for each device automatically updates, maintaining policy relevance without manual intervention while enabling rapid response to emerging threats.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10313396B2Routing and/or forwarding information driven subscription against global security policy data
Publication Date: 2019.06.04 CISCO TECHNOLOGY INC
  • US10313396B2 patent drawing
  • US10313396B2 patent drawing
  • US10313396B2 patent drawing

AI summary

Techniques are provided by which devices in a network may subscribe to a rapidly changing rules in central threat repository. The policies associated with threats are filtered so that just current attack vectors from within subnets learned via routing and/or forwarding information (at the network level of the network) are installed in the local access control list/policy database of the network devices. As routing changes occur, the list of applied policies are continually refined/revisited and pulled from a central security application. Publish/subscribe mechanisms ensure “zombie” policies are not left over in the device after reboot or routing changes occur.