Zero-Trust Data Surveillance via Dual Policy Managers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security and performance monitoring techniques fail to detect issues in zero-trust computer networks, including IP threats and data leaks, due to the lack of a network data policy manager that works in conjunction with a network device policy manager.

Innovation Solution

A data surveillance system that integrates a network data policy manager with a network device policy manager, using supervised and unsupervised machine learning to analyze each data packet through Deep Packet Inspection, establishing a rolling baseline of normal behavior and detecting anomalies by clustering packets based on protocol, user behavior, and packet content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring techniques are used, then device access control is maintained, but security issues and data leaks cannot be detected in zero-trust networks

Engineering Contradiction:
Improvedetection capabilityVSAvoidcompatibility with zero-trust architecture
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a network data policy manager as an intermediary component that bridges the gap between traditional security monitoring and zero-trust architecture. This manager collects data from multiple sources including device policy manager, data sources, and network traffic, processes it through machine learning models, and generates insights without disrupting the existing zero-trust framework. The intermediary enables advanced detection capabilities while maintaining compatibility with the zero-trust environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the security monitoring function into distinct modular components: data collection module, data processing module with machine learning models, anomaly detection module, and reporting module. This segmentation allows each component to be independently optimized and integrated into the zero-trust architecture without requiring complete system redesign, thereby improving detection capability while maintaining adaptability.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If Deep Packet Inspection is performed on each data packet, then security detection accuracy is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvepacket analysis accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies Deep Packet Inspection selectively rather than uniformly to all packets. The machine learning models first analyze packet metadata and characteristics to identify packets that require detailed inspection. Only packets flagged as potentially anomalous or matching specific risk patterns undergo full Deep Packet Inspection, reducing overall system complexity while maintaining high detection accuracy for critical threats.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary analysis of network traffic using lightweight machine learning models before applying resource-intensive Deep Packet Inspection. This preliminary action filters out normal traffic patterns and identifies suspicious packets that warrant detailed examination, thereby reducing the volume of packets requiring complex analysis and lowering overall system complexity while preserving measurement precision.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If a rolling baseline of normal behavior is established through continuous learning, then detection accuracy improves over time, but computational resources and processing time increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements periodic updates to the rolling baseline rather than continuous retraining of machine learning models. Data is collected and accumulated over defined time periods, and model retraining occurs at scheduled intervals or when sufficient data accumulates. This periodic approach maintains detection accuracy by regularly updating the baseline with new normal behavior patterns while avoiding the continuous computational overhead of constant model retraining.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system dynamically adjusts parameters of the machine learning models based on the stage of baseline establishment. During initial baseline creation, more data is collected with less aggressive model updates. As the baseline matures, the system transitions to more efficient incremental learning with adjusted learning rates and data sampling parameters, thereby improving detection accuracy over time while managing computational resource consumption and processing time.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12058153B2Data surveillance in a zero-trust network
Publication Date: 2024.08.06 FLYING CLOUD TECH INC
  • US12058153B2 patent drawing
  • US12058153B2 patent drawing
  • US12058153B2 patent drawing

AI summary

Data surveillance techniques are presented for the detection of security and/or performance issues on a zero-trust computer network. There is a network device policy manager that works in conjunction with a network data policy manager and which is in charge of performing the above data surveillance. Of special interest are those security issues where privileged data may be stolen by steganographic, data manipulation or any form of exfiltration attempts. Such attempts may be made by rogue users or admins from the inside of a network, or from outside hackers who are able to intrude into the network but can impersonate themselves as legitimate users. The above data surveillance techniques are also applied for detecting intentional or unintentional exfiltration/leak of privileged data/assets between unauthorized users/groups of the organization.