Application Packet Classifier for Industrial Firewall Rule Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing effective firewall rules in industrial networks is challenging due to the complexity of protocols like CIP, which makes it difficult to define rules for allowing desired communications between devices, especially with implicit messages that contain limited information and varying formats, requiring extensive knowledge of the protocol and devices.

Innovation Solution

A network device with a packet processing module, application classifier, and rules engine that identifies application functions based on message packets and compares them to a database of rules to allow or block communications, enabling secure communication by defining rules at an application level rather than a message packet level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional packet-level firewall rules are used to control CIP protocol communications, then security can be maintained, but the complexity of defining and configuring rules increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidfirewall rule configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter of firewall rule classification from packet-level parameters (source IP, destination IP, port numbers) to application-level parameters (CIP message types, function codes, data lengths). This allows rules to be defined based on the semantic meaning of CIP messages rather than low-level network parameters, significantly reducing configuration complexity while maintaining security

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an application classifier as an intermediary component between the packet inspection engine and the firewall rule database. This classifier translates CIP protocol messages into application-level descriptors that can be matched against high-level firewall rules, acting as a mediator that simplifies the rule configuration process while maintaining precise control over CIP communications

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If detailed packet inspection is performed to ensure security, then unauthorized access can be blocked, but the processing time and computational resources increase

Engineering Contradiction:
ImprovesecurityVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the firewall processing into multiple stages: packet capture, CIP message type identification, application classifier matching, and rule evaluation. By dividing the inspection process into discrete segments, the system can quickly eliminate non-matching packets at early stages without performing full-depth inspection on every packet, reducing overall processing time while maintaining security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial inspection by focusing only on the necessary portions of CIP messages for security validation (message type, function code, data length) rather than inspecting the entire message content. This selective inspection approach maintains security for control messages while reducing processing overhead by skipping unnecessary detailed analysis

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3026863B1Firewall with application packet classifier
Publication Date: 2021.01.13 ROCKWELL AUTOMATION TECH INC
  • EP3026863B1 patent drawingFigure 1
  • EP3026863B1 patent drawingFigure 2~3
  • EP3026863B1 patent drawingFigure 4

AI summary

An improved system for establishing rules in a firewall (104) for an industrial network is disclosed. Rules are established at an application level, identifying, for example, actions to occur between two devices (100, 108). The action may be, for example, read data table or get attribute, and each action may require multiple message packets to be transmitted between the two devices (100, 108) in order to complete. A network device (60) executing the firewall (104) is configured to receive message packets from a sending device and to inspect the message packets to determine which action the sending device is requesting to perform. If the action corresponds to a rule in the database (82), the network device (60) manages communications between the two devices (100, 108) until all message packets have been transmitted. Thus, a single action, or application, may be defined in the rules database (82) to permit multiple data packets to be communicated between the devices (100, 108).