Network Security Policy Filtering via Routing Topology
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in efficiently distributing relevant cybersecurity threat information to enterprise network endpoints due to limited memory and processing capabilities, especially with rapidly changing routing topologies and limited access control list space, leading to difficulties in ensuring only topologically relevant policies are installed and irrelevant policies are not left on devices.
Innovation Solution
A system where network devices subscribe to a central threat repository, with policies filtered to install only current attack vectors from subnets learned via routing, using publish/subscribe mechanisms to continually refine and update policies based on routing changes, and applying dynamic security policies at the access edge using routing and forwarding information as filter criteria.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If global cybersecurity threat information is distributed to all network endpoints, then network security coverage is improved, but memory and processing burdens at endpoints increase beyond their limited capabilities
Solution Approach 1:
The patent segments the global cybersecurity threat information into route-specific subsets. Each network device receives only the threat information relevant to its locally learned routes, rather than distributing all global threat data to every endpoint. This segmentation reduces the quantity of information each device must store and process while maintaining comprehensive security coverage across the network.
Solution Approach 2:
The patent implements local quality by tailoring the security policy information to each network device's specific context. Each device receives threat information filtered by its local routing table, so that device-specific memory and processing resources are utilized efficiently for locally relevant threats only, rather than uniformly distributing identical information to all endpoints.
2Reliability
If comprehensive security policies are installed on all devices, then security protection is improved, but control over topologically relevant policies becomes difficult due to limited ACL space
Solution Approach 1:
The patent extracts only the topologically relevant portion of global security policies based on each device's local routing information. By using routing tables as filter criteria, the system extracts and installs only those threat-related policies that are relevant to the device's actual network connections, leaving out irrelevant policies and preventing ACL space exhaustion.
3Speed
If security policies are updated frequently to reflect changing threats, then security responsiveness is improved, but maintaining policy relevance becomes difficult with dynamic routing topologies
Solution Approach 1:
The patent establishes a feedback mechanism where network devices report their locally learned routes back to the security system. This feedback loop allows the system to continuously update and refine which threat information is distributed to each device, ensuring that security policies remain relevant to the current network topology while responding quickly to new threats.
Solution Approach 2:
The patent makes the security policy distribution dynamic by linking it to real-time routing information. As network topology changes and devices learn new routes, the set of relevant threat information for each device automatically updates, maintaining policy relevance without manual intervention while enabling rapid response to emerging threats.
Data Source
AI summary
Techniques are provided by which devices in a network may subscribe to a rapidly changing rules in central threat repository. The policies associated with threats are filtered so that just current attack vectors from within subnets learned via routing and/or forwarding information (at the network level of the network) are installed in the local access control list/policy database of the network devices. As routing changes occur, the list of applied policies are continually refined/revisited and pulled from a central security application. Publish/subscribe mechanisms ensure “zombie” policies are not left over in the device after reboot or routing changes occur.


