Network Threat Detection via Zone-Aware Policy Annotation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current flow-based threat detection systems fail to accurately account for contextual security policies across enterprise networks, leading to misdiagnoses and improper enforcement due to lack of synchronicity between threat detection systems and access control policies.
Innovation Solution
A threat detection server that collects and annotates network flow metadata with zone definitions and security policies from various systems, enabling enterprise-wide policy monitoring and detection by consolidating and enforcing these definitions across zones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If flow-based threat detection systems rely solely on transactional telemetry and locally defined contexts, then the systems can operate independently without requiring synchronization with other security systems, but the accuracy of threat detection deteriorates due to lack of contextual security policy information
Solution Approach 1:
The patent merges flow-based threat detection with access control policy information by collecting security policies from multiple sources (firewalls, intrusion prevention systems, etc.) and integrating them into a unified policy store. This allows the threat detection system to access contextual security policy information while maintaining a centralized architecture, resolving the contradiction between detection accuracy and system complexity.
Solution Approach 2:
The patent introduces a policy store and policy collection module as intermediaries between various security systems and the threat detection engine. These intermediaries collect, normalize, and store security policies from disparate sources, enabling the threat detection system to access contextual information without direct complex connections to each security system, thus maintaining reliability while managing complexity.
2Measurement precision
If threat detection systems use locally defined security policies in isolation, then the systems can be implemented independently, but misdiagnoses and improper enforcement occur due to lack of synchronicity with access control policies
Solution Approach 1:
The patent creates a universal policy store that can store and manage security policies from multiple different sources and formats (firewall rules, intrusion prevention policies, access control lists, etc.). This multi-functional policy store enables the threat detection system to work with various policy types uniformly, improving detection precision while maintaining flexibility in integrating different security systems.
Solution Approach 2:
The patent transforms security policies from different sources into a standardized format with common parameters and structures. By normalizing policy representations, the system can accurately compare flow data against security policies regardless of their original format, improving detection precision while maintaining adaptability to integrate diverse security systems.
3Reliability
If enterprise networks have multiple disparate security systems with separate policy definitions, then each system can be configured and managed independently, but consistent policy enforcement and proper alarm prioritization cannot be achieved
Solution Approach 1:
The patent merges multiple disparate security policies into a unified policy store that consolidates firewall rules, intrusion prevention policies, and access control definitions. This centralized policy repository ensures consistent policy enforcement across the enterprise network while providing a single management interface, reducing policy management complexity despite the presence of multiple security systems.
Data Source
AI summary
In one example embodiment, a threat detection server receives metadata of a network flow in a network; a zone definition that correlates the metadata of the network flow with a first zone of network devices in the network and a second zone of network devices in the network, where the network flow was transmitted from the first zone to the second zone; and a security policy for the network flow, where the security policy is enforced on the basis of the first zone and the second zone. Based on the zone definition, the threat detection server annotates a flow record that includes the metadata with an indication of the first zone and the second zone. Based on the annotated flow record and the security policy, the threat detection server determines whether to generate a notification associated with a detection of a security threat associated with the network flow.


