Cloud Firewall Configuration via Aggregated Security Event Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current firewall configurations in computer networks are manually managed, leading to security breaches as not all security issues can be anticipated, resulting in inadequate protection against potential threats.
Innovation Solution
A cloud management system that analyzes aggregated security event data to identify likely security attacks and automatically configures firewall settings across connected client computing environments to prevent such attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual firewall rule configuration is used, then system complexity is reduced and ease of operation is maintained, but security reliability deteriorates due to inability to anticipate all security issues
Solution Approach 1:
An automated security management system acts as an intermediary between security threats and firewall configurations. This system monitors security events, analyzes threats, and automatically generates firewall rules, eliminating the need for manual configuration while improving security reliability through continuous automated protection.
Solution Approach 2:
The system performs preliminary security analysis by monitoring security events and anticipating potential threats before they exploit vulnerabilities. By proactively generating firewall rules based on predicted attack vectors, the system prevents security breaches rather than reacting to them after occurrence.
2Reliability
If manual firewall configuration is used, then automation extent is reduced, but ease of operation is maintained, but security breaches occur due to reactive rather than proactive security management
Solution Approach 1:
The firewall system performs self-service by automatically monitoring security events, analyzing threats, and configuring rules without human intervention. This self-protecting mechanism continuously adapts to new threats, maintaining high security protection while operating at full automation capacity.
Solution Approach 2:
The system implements continuous feedback loops by monitoring security events, analyzing the effectiveness of current firewall rules, and automatically adjusting configurations based on observed threats and attack patterns. This closed-loop control ensures optimal security protection through adaptive automation.
Data Source
AI summary
Disclosed are systems, methods, and computer-readable storage media for automatic firewall configuration based on aggregated cloud managed information. A cloud management device can determine, based on security event data received from a first set of client computing environments, that a security attack detected on at least one client computing environment from the first set of client computing environments is likely to occur on other client computing environments. In response to determining that the security attack detected on at least one client computing environment from the first set of client computing environments is likely to occur on other client computing environments, the cloud management device can identify a second set of client computing environments to protect from the security attack. For each client computing environment from the second set of client computing environments, the cloud management device can configure firewall settings to protect from the security attack.


