Network Workload Labeling with Segmentation Server Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing segmentation policies in network environments are vulnerable to manipulation by malicious actors who can exploit label assignment schemes, leading to security risks by altering workload attributes to gain unauthorized access.
Innovation Solution
A system that securely assigns labels to workloads based on pairing profiles and attributes, using a segmentation server to enforce label-based rules, where labels associated with pairing profiles are fixed and secure, while labels based on workload attributes are adaptable, allowing for flexible management of security and adaptability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If labels are automatically assigned to workloads based on workload attributes, then label assignment efficiency is improved, but security is worsened because malicious actors can manipulate attributes to gain unauthorized access
Solution Approach 1:
The patent segments the label assignment process into two distinct components: (1) automatic label assignment based on workload attributes for efficiency, and (2) administrator approval requirement for security. This segmentation allows the system to benefit from both automated efficiency and human oversight for security-critical decisions.
Solution Approach 2:
The patent introduces an administrator as an intermediary between the automatic label assignment process and the final label application. The administrator reviews and approves label assignments, acting as a mediator who can prevent malicious assignments while allowing legitimate automated assignments to proceed.
2Reliability
If administrator approval is required for label assignment, then security is improved, but label assignment efficiency is worsened due to manual review requirements
Solution Approach 1:
The patent applies local quality by requiring administrator approval only for certain label assignments while allowing other assignments to proceed automatically. This selective approach ensures security for critical assignments while maintaining efficiency for routine assignments.
3Reliability
If fixed labels are assigned based on pairing profiles, then security boundaries are strengthened, but adaptability to changing workload conditions is reduced
Solution Approach 1:
The patent implements dynamics by allowing labels to transition from fixed (when assigned via pairing profile) to adaptable (when administrator-approved changes are made). This enables the system to adjust security boundaries dynamically based on changing workload conditions while maintaining strong security foundations.
Data Source
AI summary
In a segmented network environment, a segmentation server assigns labels to workloads to enable the segmentation server to implement a segmentation policy based on label-based rules. A first set of labels associated with one or more label dimensions may be assigned in a secure manner by automatically assigning the labels based on a pairing profile. A second set of labels associated with different label dimensions may be assigned automatically based on workload attributes. An administrator can manage which label dimensions are assigned in a secure way based on the pairing profile and which labels are assigned in an adaptable way based on workload attributes, thereby enabling the administrator to flexibly manage the tradeoff between adaptability and security.


