Unsupervised Network Security Policy Generation from Application Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies require tedious and error-prone manual management of communication policies, especially in dynamic network environments, leading to inefficiencies and potential security vulnerabilities.

Innovation Solution

An unsupervised machine learning approach is applied to network communications to generate policies that distinguish between healthy and unhealthy interactions without predefined labels, using application fingerprints and feature clusters to create human-readable rules that adapt dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual policy management is used, then policies can be precisely configured, but the process becomes tedious and error-prone

Engineering Contradiction:
Improvepolicy configuration accuracyVSAvoidpolicy management time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically generating network security policies through machine learning analysis of communication patterns. The ML model autonomously identifies healthy and unhealthy communications and generates corresponding policies without requiring manual configuration, thereby eliminating time-consuming manual policy management while maintaining high accuracy through statistical analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual policy configuration process with an automated machine learning system. The ML model analyzes network communication data, identifies patterns, and generates policies automatically, substituting human manual operations with an intelligent automated system that reduces both time and error rates.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Manufacturing precision

If manual policy management is used, then policies can be precisely configured, but errors increase

Engineering Contradiction:
Improvepolicy configuration accuracyVSAvoidpolicy error rate
Core Design Contradiction:
Manufacturing precisionVSReliability

Solution Approach 1:

The system performs self-service by automatically generating network security policies through machine learning analysis of communication patterns. The ML model autonomously identifies healthy and unhealthy communications and generates corresponding policies without requiring manual configuration, thereby eliminating time-consuming manual policy management while maintaining high accuracy through statistical analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring network communications, comparing actual communication patterns against learned patterns, and using this feedback to refine and update policies. The ML model learns from observed communications and adjusts policies based on feedback about communication health, thereby reducing errors through continuous improvement.

Inventive Principle:
Principle #23Feedback

3Productivity

If automated policy generation is implemented, then efficiency improves, but system complexity increases

Engineering Contradiction:
Improvepolicy generation efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a machine learning model as an intermediary between raw network communication data and security policies. The ML model serves as a mediator that automatically processes communication patterns, identifies healthy and unhealthy behaviors, and generates policies, thereby improving efficiency while managing complexity through the use of an intelligent intermediate layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service by automatically generating network security policies through machine learning analysis of communication patterns. The ML model autonomously identifies healthy and unhealthy communications and generates corresponding policies without requiring manual configuration, thereby eliminating time-consuming manual policy management while maintaining high accuracy through statistical analysis.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If traditional firewall policies are used, then directional access can be controlled, but adaptability to dynamic network changes decreases

Engineering Contradiction:
Improveaccess control capabilityVSAvoidnetwork dynamic adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic policy generation by using machine learning to continuously analyze network communication patterns and automatically adapt policies to changing network conditions. The system learns from observed communications and dynamically updates policies to reflect current network behavior, thereby achieving both access control and adaptability to dynamic network changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring network communications, comparing actual communication patterns against learned patterns, and using this feedback to refine and update policies. The ML model learns from observed communications and adjusts policies based on feedback about communication health, thereby reducing errors through continuous improvement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250240329A1Statistical Network Application Security Policy Generation
Publication Date: 2025.07.24 ZSCALER INC
  • US20250240329A1 patent drawing
  • US20250240329A1 patent drawing
  • US20250240329A1 patent drawing

AI summary

A method for automatically generating network communication policies employs unsupervised machine learning on unlabeled network data representing communications between applications on multiple computer systems. This approach uniquely derives policy rules without predefined labels or user-defined communication categories, ensuring automated rules complement existing user-generated policies by excluding them during training. The method validates network interactions by enforcing rules that leverage application fingerprints and identified feature clusters to distinguish permitted from prohibited communications. Additional techniques include dynamically adapting policies, utilizing decision trees, frequent itemset discovery, and evolutionary algorithms. Suspicious applications are flagged, and malicious data is excluded from training. The system uses aggregated flows, MapReduce processing, and simulated annealing optimization, providing human-readable, periodically retrained rules for balanced network security management.