Segmentation Server Vulnerability Exposure Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manually configuring segmentation policies for complex networks with many workloads is resource-intensive and increases security risks if not properly configured.

Innovation Solution

A system and method that uses a segmentation server to generate vulnerability exposure scores for workloads, aggregating data to provide a presentation of vulnerability information and automatically generate a modified segmentation policy to reduce exposure to vulnerabilities while maintaining operational integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manually configuring segmentation policy by defining individual rules, then security control precision is improved, but administrative burden and resource consumption increase

Engineering Contradiction:
Improvesecurity control precisionVSAvoidadministrative efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables self-service by allowing workloads to automatically discover and register themselves in the segmentation server, eliminating the need for manual administrator configuration. Workloads autonomously provide their information (IP address, port, service type) and the system automatically generates segmentation policies based on discovered connections, transforming a manual process into an automated self-configure system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameters of segmentation policy configuration from manual rule definition to automated parameter discovery. Instead of administrators manually defining allow/deny rules, the system automatically discovers connectivity parameters (which workloads connect to which ports) and transforms this data into segmentation policies, fundamentally changing how segmentation is configured.

Inventive Principle:
Principle #35Parameter changes

2Manufacturing precision

If manually configuring segmentation policy, then policy accuracy is improved, but time consumption and resource requirements increase

Engineering Contradiction:
Improvepolicy accuracyVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by having workloads automatically discover and register their connectivity information before segmentation policies are needed. The segmentation server proactively queries workloads for their IP addresses, ports, and service types, and automatically maps connectivity relationships, so that when policies are generated, all necessary information is already prepared and the system can immediately produce accurate segmentation rules without time-consuming manual configuration.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If increasing segmentation policy restrictions to improve security, then vulnerability exposure is reduced, but workload connectivity and operational integrity may be impeded

Engineering Contradiction:
Improvevulnerability exposureVSAvoidworkload connectivity
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system implements feedback by continuously monitoring actual workload connectivity and using this information to refine segmentation policies. The segmentation server receives feedback from workloads about their real communication patterns and adjusts the segmentation policies accordingly, ensuring that security restrictions are based on actual needs rather than assumed requirements, thereby maintaining operational integrity while reducing vulnerability exposure.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies local quality by tailoring segmentation policies to specific local connectivity requirements rather than applying uniform restrictions. Instead of blanket deny-all rules, the system creates targeted allow rules for specific workload pairs based on their actual communication needs, allowing fine-grained control that secures vulnerable ports while preserving necessary connectivity for workloads that truly need to communicate.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11665191B2Generating vulnerability exposure scores in a segmented computing environment
Publication Date: 2023.05.30 ILLUMIO INC
  • US11665191B2 patent drawing
  • US11665191B2 patent drawing
  • US11665191B2 patent drawing

AI summary

A segmentation server generates vulnerability exposure scores associated with workloads operating in a segmented computing environment. The segmentation server may automatically aggregate the vulnerability exposure scores in various ways to generate vulnerability exposure information representative of workloads in an administrative domain controlled by the segmentation server. The aggregated vulnerability exposure information may be presented in a manner that enables an administrator to easily evaluate different segmentation strategies and assess the risks associated with each of them. Moreover, the segmentation server can automatically generate a segmentation policy that modifies a configured segmentation strategy based on the vulnerability exposure scores to reduce exposure to certain vulnerabilities without impeding operation of the workloads.