Zero-Trust Data Surveillance via Dual Policy Managers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security and performance monitoring techniques fail to detect issues in zero-trust computer networks, including IP threats and data leaks, due to the lack of a network data policy manager that works in conjunction with a network device policy manager.
Innovation Solution
A data surveillance system that integrates a network data policy manager with a network device policy manager, using supervised and unsupervised machine learning to analyze each data packet through Deep Packet Inspection, establishing a rolling baseline of normal behavior and detecting anomalies by clustering packets based on protocol, user behavior, and packet content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security monitoring techniques are used, then device access control is maintained, but security issues and data leaks cannot be detected in zero-trust networks
Solution Approach 1:
The patent introduces a network data policy manager as an intermediary component that bridges the gap between traditional security monitoring and zero-trust architecture. This manager collects data from multiple sources including device policy manager, data sources, and network traffic, processes it through machine learning models, and generates insights without disrupting the existing zero-trust framework. The intermediary enables advanced detection capabilities while maintaining compatibility with the zero-trust environment.
Solution Approach 2:
The system segments the security monitoring function into distinct modular components: data collection module, data processing module with machine learning models, anomaly detection module, and reporting module. This segmentation allows each component to be independently optimized and integrated into the zero-trust architecture without requiring complete system redesign, thereby improving detection capability while maintaining adaptability.
2Measurement precision
If Deep Packet Inspection is performed on each data packet, then security detection accuracy is improved, but system complexity and processing overhead increase
Solution Approach 1:
The system applies Deep Packet Inspection selectively rather than uniformly to all packets. The machine learning models first analyze packet metadata and characteristics to identify packets that require detailed inspection. Only packets flagged as potentially anomalous or matching specific risk patterns undergo full Deep Packet Inspection, reducing overall system complexity while maintaining high detection accuracy for critical threats.
Solution Approach 2:
The system performs preliminary analysis of network traffic using lightweight machine learning models before applying resource-intensive Deep Packet Inspection. This preliminary action filters out normal traffic patterns and identifies suspicious packets that warrant detailed examination, thereby reducing the volume of packets requiring complex analysis and lowering overall system complexity while preserving measurement precision.
3Measurement precision
If a rolling baseline of normal behavior is established through continuous learning, then detection accuracy improves over time, but computational resources and processing time increase
Solution Approach 1:
The system implements periodic updates to the rolling baseline rather than continuous retraining of machine learning models. Data is collected and accumulated over defined time periods, and model retraining occurs at scheduled intervals or when sufficient data accumulates. This periodic approach maintains detection accuracy by regularly updating the baseline with new normal behavior patterns while avoiding the continuous computational overhead of constant model retraining.
Solution Approach 2:
The system dynamically adjusts parameters of the machine learning models based on the stage of baseline establishment. During initial baseline creation, more data is collected with less aggressive model updates. As the baseline matures, the system transitions to more efficient incremental learning with adjusted learning rates and data sampling parameters, thereby improving detection accuracy over time while managing computational resource consumption and processing time.
Data Source
AI summary
Data surveillance techniques are presented for the detection of security and/or performance issues on a zero-trust computer network. There is a network device policy manager that works in conjunction with a network data policy manager and which is in charge of performing the above data surveillance. Of special interest are those security issues where privileged data may be stolen by steganographic, data manipulation or any form of exfiltration attempts. Such attempts may be made by rogue users or admins from the inside of a network, or from outside hackers who are able to intrude into the network but can impersonate themselves as legitimate users. The above data surveillance techniques are also applied for detecting intentional or unintentional exfiltration/leak of privileged data/assets between unauthorized users/groups of the organization.


