Automated Security Zone Discovery via Network Flow Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Many enterprises lack an up-to-date inventory of security zones in their networks, making it difficult to manage security compliance, optimize network performance, and migrate systems effectively, as current methods rely on unreliable manual data collection by network administrators.

Innovation Solution

An automated method and system that use an elimination-based inference methodology to discover security classifications by comparing enterprise security policies with observed network flows, employing feasibility sets and a staged information collection approach to accurately assign security classifications to network areas without requiring special credentials or network software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual data collection by network administrators is used, then existing methods can be simple to implement, but the obtained information is unreliable and often outdated

Engineering Contradiction:
Improvereliability of security zone informationVSAvoidautomation of data collection
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system performs self-service by automatically discovering security zone information through network flow analysis without requiring network administrators to manually provide data. The automated discovery process independently collects, analyzes, and maintains security zone inventory, eliminating dependency on human administrators for data provision.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual data collection process with an automated computational system that uses network flow analysis algorithms. Instead of relying on human administrators to manually query and report security zone information, the system automatically analyzes network flows to discover and maintain the security zone inventory.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If automated discovery method is implemented, then up-to-date security zone information can be obtained reliably, but the system complexity increases

Engineering Contradiction:
Improveaccuracy of security classificationVSAvoidcomplexity of discovery system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system achieves universality by using a single automated discovery mechanism that can accurately classify security zones across diverse network environments. The network flow analysis approach is universally applicable to different network topologies, organizational structures, and security policies, providing consistent accurate classification without requiring environment-specific complex subsystems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies parameter changes by transforming network flow data into security classification assignments through systematic analysis. The system changes the state of raw network flow parameters into meaningful security zone classifications by analyzing flow characteristics against security policies, achieving accurate measurement through parameter transformation rather than complex system architecture.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If manual inventory collection is used, then implementation is straightforward, but the process is time-consuming and labor-intensive

Engineering Contradiction:
Improvespeed of inventory acquisitionVSAvoidtime required for data collection
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system implements continuous useful action by continuously monitoring network flows and automatically updating the security zone inventory. Rather than performing periodic manual inventory collection, the system continuously discovers and maintains security zone information as network traffic occurs, eliminating downtime and labor requirements while providing up-to-date inventory always.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent replaces the manual mechanical process of inventory collection with automated computational analysis of network flows. The system uses algorithms to automatically process network flow data, extract security zone information, and maintain the inventory without human intervention, dramatically increasing productivity and eliminating time loss associated with manual data gathering.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If comprehensive security zone information is collected, then network management and compliance can be improved, but the overhead of data collection increases

Engineering Contradiction:
Improvecompleteness of security zone inventoryVSAvoidoverhead of data collection
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies extraction by selectively extracting only the necessary security zone information from network flow data. Rather than collecting all possible network data, the system extracts and analyzes only the flow characteristics relevant to security classification, such as source/destination addresses, ports, and protocols, thereby obtaining complete security zone inventory with minimal data collection overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses parameter changes to transform network flow parameters into security classification information. By analyzing changes in flow parameters such as connection states, address assignments, and traffic patterns, the system derives comprehensive security zone inventory without needing to collect all possible network data, reducing overhead while maintaining completeness.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8826425B2System and method for automatically discovering security classification of hosts
Publication Date: 2014.09.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8826425B2 patent drawing
  • US8826425B2 patent drawing
  • US8826425B2 patent drawing

AI summary

A system and method for discovering security classifications of network areas includes representing actually allowed network flows and flows permitted by a security policy in a format that enables comparison. The actually allowed network flows and the security policy are provided in a networked computing environment including network areas, wherein each network area is a collection of one or more computing and network devices, and enterprise security policy defines security requirements for security classifications. An assignment of security classifications to network areas is determined by comparing the actually allowed network flows with the flows permitted by the security policy.