Segmentation Server Core Service Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Poorly configured segmentation policies in data centers can inadvertently block access to core services essential for application operation, leading to security and operational issues.
Innovation Solution
A segmentation server that updates enforcement of a segmentation policy by detecting core services using workload characteristics, applying classification models, port matching, or a combination thereof, and assigning labels to workloads to enable appropriate segmentation rules enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a segmentation policy is strictly enforced to enhance security, then security is improved, but access to core services may be blocked
Solution Approach 1:
The segmentation server automatically detects core services and updates segmentation rules without requiring manual administrator intervention. The system self-adjusts by identifying workloads providing core services through classification models and port matching, then automatically modifying segmentation policies to allow necessary traffic while maintaining security for non-core services
Solution Approach 2:
The system implements a feedback loop where the segmentation server continuously monitors workload characteristics, detects core services, and updates segmentation rules accordingly. This closed-loop approach allows the system to learn from traffic patterns and automatically adjust policies to balance security requirements with operational needs
2Ease of operation
If manual configuration of segmentation policies is used to allow core services, then access to core services is maintained, but the complexity of policy configuration increases
Solution Approach 1:
The segmentation server performs automatic core service detection and rule generation, eliminating the need for administrators to manually identify and configure rules for each core service. The system autonomously analyzes workload characteristics, applies classification models, and generates appropriate segmentation rules without human intervention
Solution Approach 2:
The patent replaces manual administrative configuration with automated machine-based detection and rule generation. Classification models and port matching algorithms substitute for human analysis, automatically identifying core services and generating segmentation rules based on detected traffic patterns and workload characteristics
3Reliability
If core service detection is not implemented, then segmentation policy enforcement is simple, but essential services may be inadvertently blocked
Solution Approach 1:
The segmentation server performs preliminary detection of core services before enforcing segmentation rules. By proactively identifying workloads that provide core services through classification models and port matching, the system prepares appropriate rules in advance, ensuring that essential services are protected from being blocked by subsequent security enforcement
Solution Approach 2:
The core service detection mechanism acts as an intermediary between the segmentation policy and the actual traffic enforcement. The detection layer analyzes workload characteristics and generates a classification that informs the segmentation engine, creating a buffer that prevents direct blocking of core services while maintaining security for other traffic
Data Source
AI summary
A segmentation server updates enforcement of a segmentation policy based on detection of core services. The segmentation server obtains characteristics of workloads and identifies workloads that provide core services using port matching, supervised learning based classification, semi supervised learning based classification, or a combination thereof. The segmentations server applies labels to workloads identified as core service providers indicative of the detection. Rules of the segmentation are distributed to enforcement modules based on the label sets of associated workloads to enable the enforcement modules to enforce the segmentation policy. Detection of core services reduces the likelihood of administrator inadvertently enforcing a policy that blocks essential core services.


