Segmentation Server Automates Network Policy Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manually configuring segmentation policies for complex networks with numerous workloads is burdensome and increases security risks if not properly configured.

Innovation Solution

A segmentation server identifies user groups and associated label sets to generate rules for controlling workload communications, distributing management instructions to enforce these rules across operating system instances, while also monitoring traffic flows to dynamically adjust policies based on observed traffic patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a system administrator manually configures segmentation policies for complex networks with numerous workloads, then the segmentation policy can be customized to specific security requirements, but the administrative burden and time consumption increase significantly

Engineering Contradiction:
Improvesecurity configuration accuracyVSAvoidpolicy configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the segmentation server automatically generates segmentation policies by monitoring traffic flows between workloads and analyzing communication patterns. The system self-configures security rules without requiring manual administrator intervention for each policy decision, thereby reducing configuration time while maintaining security requirements through automated traffic analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The segmentation server continuously monitors actual traffic flows between workloads and uses this feedback to dynamically adjust and optimize segmentation policies. By observing real communication patterns and applying this feedback to policy generation, the system achieves accurate security configurations that adapt to actual network usage without requiring extensive manual tuning.

Inventive Principle:
Principle #23Feedback

2Reliability

If segmentation policies are manually configured for complex networks, then specific security requirements can be addressed, but the complexity of administration and resource requirements increase

Engineering Contradiction:
Improvesecurity policy effectivenessVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The segmentation server performs self-service by automatically generating segmentation policies based on monitored traffic flows. The system independently analyzes communication patterns between workloads and formulates appropriate security rules, eliminating the need for complex manual configuration processes and reducing administrative overhead while maintaining effective security coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The segmentation server provides multi-functional capabilities by combining traffic flow monitoring, policy analysis, rule generation, and distribution to operating system instances into a single unified system. This universal approach handles diverse security requirements across multiple workloads through a centralized platform, reducing overall administrative complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If segmentation policies are not carefully configured, then administrative effort is reduced, but security risks increase

Engineering Contradiction:
Improvepolicy configuration easeVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The segmentation server automatically generates secure segmentation policies by monitoring actual traffic flows between workloads. This self-service approach ensures that security rules are carefully configured based on real communication patterns without requiring manual intervention, thereby maintaining high security standards while simplifying the configuration process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The segmentation server performs preliminary analysis of traffic flows and communication patterns before generating segmentation policies. By pre-analyzing actual network usage and identifying legitimate communication requirements, the system prepares accurate security rules in advance, ensuring that policies are both secure and aligned with actual operational needs before being enforced.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11381603B2User-based visibility and control of a segmentation policy
Publication Date: 2022.07.05 ILLUMIO INC
  • US11381603B2 patent drawing
  • US11381603B2 patent drawing
  • US11381603B2 patent drawing

AI summary

A segmentation server enables user-based management of a segmentation policy. Administrators belonging to different user groups may have different limited visibility into traffic flows controlled by the segmentation policy and may be assigned different privileges with respect to viewing, creating, and modifying rules of the segmentation policy. Thus, the burden of administering the segmentation policy may be distributed between administrators associated with different user groups that each may have responsibility for a different segment.