White-list Network Security Migration via Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network configurations in large data center networks are complex and prone to errors, leading to inconsistencies that can cause significant problems, as the configurations defined by a centralized controller may not accurately reflect the intended behavior of the network.

Innovation Solution

The implementation of systems and methods for migrating and maintaining white-list security models, which involve identifying and forwarding network traffic based on a white-list security model by generating and implementing a permit-access policy, ensuring that only authorized traffic is allowed, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized controller programs network configurations for large data center networks, then network management and control is simplified, but configuration errors and inconsistencies increase due to complexity

Engineering Contradiction:
Improvenetwork managementVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary validation of network configurations before they are deployed. By checking configurations in advance against expected network states and detecting potential issues beforehand, the system prevents configuration errors from causing network problems while maintaining centralized control simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors network actual behavior and compares it against intended configurations, providing feedback loops that detect inconsistencies between what should be configured and what is actually happening. This enables automatic detection and correction of configuration drift and errors.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If network configurations are made more complex to handle advanced network functions, then network functionality is enhanced, but error detection becomes more difficult

Engineering Contradiction:
Improvenetwork functionalityVSAvoidconfiguration error detection
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system breaks down complex network configurations into smaller, manageable components and validates each segment independently. By segmenting the configuration validation process, the system can detect errors in specific areas without being overwhelmed by the overall complexity of the network setup.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements visual indicators and status representations that make configuration states visible and detectable. By using clear visual feedback to show configuration status, compliance, and potential issues, the system makes error detection easier even for complex multi-layer network configurations.

Inventive Principle:
Principle #32Color changes

3Reliability

If a white-list security model is implemented to ensure network security, then unauthorized access is prevented, but network traffic management complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidtraffic management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically manages the white-list by monitoring network traffic patterns and configurations, then automatically adding authorized traffic entries to the white-list without manual intervention. This self-service approach maintains strong security while reducing operational complexity through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts white-list parameters based on detected network conditions and traffic patterns. By automatically updating allow-list entries based on actual network behavior rather than static rules, the system maintains security effectiveness while simplifying traffic management through adaptive automation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10587621B2System and method for migrating to and maintaining a white-list network security model
Publication Date: 2020.03.10 CISCO TECHNOLOGY INC
  • US10587621B2 patent drawing
  • US10587621B2 patent drawing
  • US10587621B2 patent drawing

AI summary

Systems, methods, and computer-readable media for migrating to and maintaining a white-list network security model. Network traffic identified from permit-all access logs can be analyzed to determine whether it should be white-listed, and if so, a specific permit-access, without logging, policy is generated for the identified network traffic. The addition of specific permit-access policies is repeated on permit-all access logs, at which point, permit-all access policy is converted into deny-all access. In some examples, a system or method can obtain hit counts, from both hardware (eg: TCAM) and software tables, for the specific permit-access policy to determine existence of identified network traffic over a period of time. After analyzing hit counts, the specific permit-access policy can either continue to exist or be removed to maintain a white-list network security model.