Subnet Policy Enforcement via Client Profile Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computer networks, devices may be incorrectly assigned to subnets, leading to improper policy application and potential security vulnerabilities, as the current subnet assignment process is not perfect and lacks effective verification mechanisms.

Innovation Solution

A method that involves monitoring network traffic to determine client device profiles, comparing them with subnet profiles, and taking corrective actions such as reassignment or alert generation when mismatches are found, ensuring devices are on the correct subnet and applying appropriate policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are assigned to subnets using traditional methods, then network setup is simple and fast, but incorrect assignments occur leading to security vulnerabilities and improper policy application

Engineering Contradiction:
Improvesubnet assignment accuracyVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system continuously monitors network traffic and compares observed device characteristics against expected subnet profiles. When mismatches are detected, the system provides feedback by generating alerts and automatically correcting assignments, creating a closed-loop verification mechanism that ensures reliability without requiring complex manual verification processes

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The verification system operates autonomously by automatically monitoring traffic, detecting mismatches, and correcting assignments without requiring manual intervention. The system self-verifies subnet assignments and self-corrects errors, reducing the need for complex administrative procedures while maintaining high accuracy

Inventive Principle:
Principle #25Self-service

2Manufacturing precision

If subnet assignment verification is implemented, then policy application accuracy improves, but network traffic monitoring and processing overhead increases

Engineering Contradiction:
Improvepolicy application precisionVSAvoidtraffic processing energy consumption
Core Design Contradiction:
Manufacturing precisionVSUse of energy by moving object

Solution Approach 1:

The system extracts only the essential characteristics from network traffic (such as user agent strings, protocol types, and connection patterns) for verification purposes, rather than processing the entire traffic stream. This selective extraction approach maintains precise policy application while minimizing processing overhead and energy consumption

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The verification mechanism performs partial monitoring by focusing on specific traffic parameters that are most indicative of device type and subnet compatibility. Rather than comprehensive analysis of all traffic, the system applies sufficient monitoring to achieve accurate verification with reduced computational resources

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9813298B2Applying policies to subnets
Publication Date: 2017.11.07 IBOSS INC
  • US9813298B2 patent drawing
  • US9813298B2 patent drawing
  • US9813298B2 patent drawing

AI summary

Associations are maintained among a plurality of subnets, policies, and client types. Each subnet has an associated client type and policy. For a particular client device, (i) a client type of the particular client device, and (ii) a client type associated with the subnet on which the particular client device is hosted is determined. For the particular client device, (i) the determined client type of the particular client device with (ii) the determined client type associated with the subnet on which the particular client device is hosted is compared. Responsive to a determination that the client type of the particular client device matches the client type associated with the subnet that hosts the particular client device, a policy is applied to the particular client device.