Adaptive network security using zero trust microsegmentation

US2024356979A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2024356979-A1
Application numberUS-202418620699-A
CountryUS
Kind codeA1
Filing dateMar 28, 2024
Priority dateApr 24, 2023
Publication dateOct 24, 2024
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Zero trust and micro-segmentation techniques may be collectively used to enhance network security. To establish, refine, and enforce a zero-trust least-privileged policy, the network may be segmented to put each device of the network into a respective network of one, which forces all network traffic to pass through a zero-trust gatekeeper. The gatekeeper may then monitor and analyze the traffic to establish, refine, and enforce the zero-trust least-privileged policy, which reduces network access to only a limited set of network actions and/or paths. Using the gatekeeper, network traffic may be monitored to progressively establish the policy as well as to continually refine the policy. Recommended actions may be determined based on the analysis of the monitored network traffic and provided to the user to allow user feedback on the communication rules of zero-trust policy.

First claim

Opening claim text (preview).

We claim: 1 . A zero-trust microsegmentation method comprising: collecting information associated with devices of a network; determining, based on the collected information, a plurality of network microsegments; determining an initial zero-trust security policy in which communication permissions for the devices of the network are denied by default unless otherwise allowed, the communication permissions including one or more communication dimensions; analyzing network traffic under the initial zero-trust security policy; and adapting the initial zero-trust security policy, based on the analysis of the network traffic, to adjust the communication permissions for the one or more communication dimensions to generate an adapted zero-trust security policy including one or more modifications to the one or more communication dimensions. 2 . The method of claim 1 , further comprising: analyzing network traffic under the adapted zero-trust security policy; and adapting the adapted zero-trust security policy, based on the analysis of the network traffic under the adapted zero-trust security policy, to adjust the communication permissions for another of the one or more communication dimensions to generate a further adapted zero-trust security policy including one or more modifications to the other of the one or more communication dimensions; and implementing the further adapted zero-trust security policy. 3 . The method of claim 2 , further comprising iteratively performing: the analyzing network traffic under the adapted zero-trust security policy, the adapting the adapted zero-trust security policy, and the implementing the further adapted zero-trust security policy. 4 . The method of claim 1 , wherein the one or more communication dimensions include an internet-intranet dimension defining a restrictiveness distinction between internet traffic and intranet traffic. 5 . The method of claim 4 , wherein the internet traffic is subject to more restrictions than intranet traffic. 6 . The method of claim 1 , wherein the one or more communication dimensions include an input-output dimension defining a restrictiveness distinction between input traffic and output traffic. 7 . The method of claim 1 , wherein the one or more communication dimensions include a segment dimension defining a restrictiveness distinction between inter-segment traffic and intra-segment traffic. 8 . The method of claim 1 , wherein the one or more communication dimensions include a port dimension defining a port-based traffic restrictiveness distinction. 9 . The method of claim 1 , wherein the one or more communication dimensions include a path dimension defining a communication path-based traffic restrictiveness distinction. 10 . The method of claim 1 , wherein the one or more communication dimensions include a user dimension defining a user-based traffic restrictiveness distinction and/or a user group-based traffic restrictiveness distinction. 11 . The method of claim 1 , wherein the one or more communication dimensions include an inter-group dimension defining am inter-group traffic restrictiveness distinction. 12 . The method of claim 1 , wherein the one or more communication dimensions include an intra-group dimension defining an intra-group traffic restrictiveness distinction. 13 . The method of claim 1 , wherein the one or more communication dimensions include an application dimension defining an application-based traffic restrictiveness distinction. 14 . The method of claim 1 , wherein adapting the initial zero-trust security policy comprises progressively increasing a restrictiveness of the one or more communication dimensions for the initial zero-trust security policy to generate the adapted zero-trust security policy, wherein between each progressive increase in restrictiveness, an incremental zero-trust security policy is implemented for a current progression, network traffic under the incremental zero-trust security policy is analyzed, and a next progression with increased restrictiveness is based on the analysis of the network traffic under the incremental zero-trust security policy. 15 . The method of claim 1 , wherein adapting the initial zero-trust security policy comprises adjusting a degree of enforcement of the communication permissions. 16 . The method of claim 1 , further comprising continually observing denied network traffic and providing a notification of the denied network traffic to a user, wherein feedback is receivable in response to the notification. 17 . The method of claim 1 , further comprising establishing the network, wherein each device of the network is in its own network of one. 18 . The method of claim 17 , wherein the networks of one are configured to cause all device traffic to traverse a gatekeeper configured as a default gateway for the devices. 19 . The method of claim 1 , wherein one or more of the devices of the network comprise a respective local zero-trust agent configured to provide zero-trust least-privilege network management. 20 . An apparatus comprising: one or more processors; and a memory for storing computer readable instructions that, when executed by the one or more processors, cause the apparatus to: collect information associated with devices of a network; determine, based on the collected information, a plurality of network microsegments; determine an initial zero-trust security policy in which communication permissions for the devices of the network are denied by default unless otherwise allowed, the communication permissions including one or more communication dimensions; analyze network traffic under the initial zero-trust security policy; and adapt the initial zero-trust security policy, based on the analysis of the network traffic. to adjust the communication permissions for the one or more communication dimensions to generate an adapted zero-trust security policy including one or more modifications to the one or more communication dimensions.

Assignees

Inventors

Classifications

  • Filtering policies (mail message filtering H04L51/212) · CPC title

  • involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved (negotiation of communication capabilities H04L69/24) · CPC title

  • Filtering by address, protocol, port number or service, e.g. IP-address or URL · CPC title

  • Grouping of entities · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2024356979A1 cover?
Zero trust and micro-segmentation techniques may be collectively used to enhance network security. To establish, refine, and enforce a zero-trust least-privileged policy, the network may be segmented to put each device of the network into a respective network of one, which forces all network traffic to pass through a zero-trust gatekeeper. The gatekeeper may then monitor and analyze the traffic…
Who is the assignee on this patent?
Colortokens Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Oct 24 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).