Zero Trust Perimeter Creation via Traffic Flow Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Zero Trust networking, enterprise system administrators face challenges in creating network policies or perimeters for endpoints or identities due to the difficulty in identifying all destination IP addresses used by applications or services, especially with dynamic changes and unknown connections like content delivery networks (CDN) and third-party services, requiring manual steps and extensive knowledge of network services and ports.

Innovation Solution

A computer-implemented method that performs primary cluster analysis on classified and unclassified traffic flows to associate unclassified flows with common services, using attributes like bytes transmitted, packets, data rate, and DNS names, and provides this determination to a network security management system to create baseline security profiles and modify user access policies, allowing for automated whitelisting of IP addresses without decrypting traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual identification of all destination IP addresses is performed, then network policy accuracy is improved, but administrative time and effort increase significantly

Engineering Contradiction:
Improvenetwork policy accuracyVSAvoidadministrative time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically discovering and classifying network traffic flows without requiring administrator intervention. The clustering algorithm autonomously identifies patterns in traffic data, groups flows by service, and generates network policies automatically, eliminating the need for manual IP address identification while maintaining high accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of identifying and tracking IP addresses with an automated computational system. The clustering algorithm processes traffic flow data computationally, substituting human administrative effort with machine-based automatic classification and policy generation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If complete knowledge of all network services and IP addresses is required, then security policy effectiveness is improved, but device complexity and knowledge requirements increase

Engineering Contradiction:
Improvesecurity policy effectivenessVSAvoidknowledge requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system eliminates the need for administrator knowledge about network services by performing self-service discovery. The clustering algorithm automatically analyzes traffic patterns, identifies services being used, and determines appropriate network policies without requiring human expertise in network protocols or service configurations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary clustering system that acts as a mediator between raw network traffic data and security policies. This intermediary automatically processes and interprets traffic flows, translating complex network data into actionable policy decisions without requiring administrators to understand the underlying technical details.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual tracking of dynamic network destinations is performed, then network control is improved, but productivity decreases due to tedious processes

Engineering Contradiction:
Improvenetwork controlVSAvoidpolicy creation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system handles dynamic network destinations by continuously monitoring and re-clustering traffic flows. As new IP addresses and services emerge, the clustering algorithm dynamically adapts to these changes, automatically updating service groupings and network policies to maintain effective control without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically detecting changes in network traffic patterns and updating policies in real-time. The clustering mechanism continuously processes new traffic data, identifies emerging services, and adjusts network controls autonomously, eliminating the need for manual tracking while maintaining high productivity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11765190B2Method for creating a zero trust segmented network perimeter for an endpoint or identity
Publication Date: 2023.09.19 BLACKBERRY LTD
  • US11765190B2 patent drawing
  • US11765190B2 patent drawing
  • US11765190B2 patent drawing

AI summary

Methods and devices are provided for determining a service associated with an unclassified traffic flow in a computer network. Classification information for a plurality of classified traffic flows in the computer network are obtained that indicate an association between each of the classified flows and a service. A primary cluster analysis is performed on the plurality of classified flows and the unclassified flow to associate the unclassified flow to a group of classified flows having a common service. The association between the unclassified flow and the common service is provided to a network security management system.