Cloud Firewall Configuration via Aggregated Security Event Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewall configurations in computer networks are manually managed, leading to security breaches as not all security issues can be anticipated, resulting in inadequate protection against potential threats.

Innovation Solution

A cloud management system that analyzes aggregated security event data to identify likely security attacks and automatically configures firewall settings across connected client computing environments to prevent such attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual firewall rule configuration is used, then system complexity is reduced and ease of operation is maintained, but security reliability deteriorates due to inability to anticipate all security issues

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An automated security management system acts as an intermediary between security threats and firewall configurations. This system monitors security events, analyzes threats, and automatically generates firewall rules, eliminating the need for manual configuration while improving security reliability through continuous automated protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security analysis by monitoring security events and anticipating potential threats before they exploit vulnerabilities. By proactively generating firewall rules based on predicted attack vectors, the system prevents security breaches rather than reacting to them after occurrence.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual firewall configuration is used, then automation extent is reduced, but ease of operation is maintained, but security breaches occur due to reactive rather than proactive security management

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfiguration automation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The firewall system performs self-service by automatically monitoring security events, analyzing threats, and configuring rules without human intervention. This self-protecting mechanism continuously adapts to new threats, maintaining high security protection while operating at full automation capacity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops by monitoring security events, analyzing the effectiveness of current firewall rules, and automatically adjusting configurations based on observed threats and attack patterns. This closed-loop control ensures optimal security protection through adaptive automation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10567344B2Automatic firewall configuration based on aggregated cloud managed information
Publication Date: 2020.02.18 CISCO TECHNOLOGY INC
  • US10567344B2 patent drawing
  • US10567344B2 patent drawing
  • US10567344B2 patent drawing

AI summary

Disclosed are systems, methods, and computer-readable storage media for automatic firewall configuration based on aggregated cloud managed information. A cloud management device can determine, based on security event data received from a first set of client computing environments, that a security attack detected on at least one client computing environment from the first set of client computing environments is likely to occur on other client computing environments. In response to determining that the security attack detected on at least one client computing environment from the first set of client computing environments is likely to occur on other client computing environments, the cloud management device can identify a second set of client computing environments to protect from the security attack. For each client computing environment from the second set of client computing environments, the cloud management device can configure firewall settings to protect from the security attack.