Dynamic Segment Prefix Learning for Intent-Based Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems struggle to implement fine-grained intent-based security policies due to the dynamic learning of LAN segment prefixes, which are not synchronized automatically, leading to manual intervention and potential misconfigurations.
Innovation Solution
A cloud-based network management system automatically translates intent-based security policies into segment-specific queries, allowing CPE devices to dynamically learn and synchronize LAN segment prefixes without human intervention, enabling fine-grained security policies across multiple sites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual intervention is used to configure network segment prefixes, then configuration accuracy can be controlled, but productivity decreases and human error increases
Solution Approach 1:
CPE devices automatically query and receive network segment prefixes from the service orchestrator without requiring manual configuration. The system enables self-service operation where devices autonomously synchronize their forwarding tables with the latest network segment information, eliminating the need for human intervention in routine prefix distribution.
Solution Approach 2:
The service orchestrator maintains a database of network segment prefixes and uses this feedback mechanism to provide updated prefix information to CPE devices upon query. This closed-loop feedback system ensures that devices receive the most current network segment data, maintaining configuration accuracy while operating automatically.
2Measurement precision
If fine-grained segment-level security policies are implemented, then security precision improves, but device complexity increases
Solution Approach 1:
The system segments network policies at the LAN segment level rather than treating entire networks as single units. By dividing the network into manageable segments with unique prefixes, the system enables fine-grained security control for specific workgroups while maintaining manageable complexity through hierarchical organization.
Solution Approach 2:
The service orchestrator acts as an intermediary between intent-based security policies and actual network configuration. It translates high-level intent policies into segment-specific queries and manages the complexity of policy translation, shielding individual CPE devices from complex policy processing while enabling precise segment-level control.
3Ease of operation
If distributed synchronization is used, then ease of operation improves, but loss of information may increase
Solution Approach 1:
CPE devices perform preliminary queries to the service orchestrator to retrieve network segment prefixes before needing to implement security policies. This advance action ensures that devices have the necessary information ready and eliminates information loss by proactively obtaining complete prefix data from the centralized database.
Solution Approach 2:
The service orchestrator provides feedback in the form of complete network segment prefix information to querying CPE devices. This feedback mechanism ensures information completeness by returning full prefix datasets, preventing information loss while enabling distributed synchronization across the network.
Data Source
AI summary
In an example, systems and methods enable automatic implementation of intent-based security policies in a network system, such as a software-defined wide area network system, in which network segment prefixes for network segments at one or more sites are dynamically learned. A service orchestrator controller translates an intent-based security policy input by a user to a security policy for a first site. The security policy for the first site specifies a segment-specific queryable resource associated with a second site. To implement the security policy, a device associated with the first site queries the segment-specific queryable resource associated with the second site, and updates one or more forwarding tables of the device with the network segment prefixes associated with one or more network segments at the second site received in response to the query. The first site forwards network traffic to the second site based on the updated forwarding tables.


