Declarative Firewall Rule Generation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing firewall rule sets is challenging due to their complexity, requiring large IT security teams to maintain tens of thousands or hundreds of thousands of rules, and existing technologies fail to efficiently generate and maintain these rules at a high level of abstraction, allowing cyber threats and advanced attacks to breach internal networks.

Innovation Solution

The method involves receiving a declarative policy associated with a computer network security policy, collecting information from external systems of record, generating a firewall rule set at a lower level of abstraction, and provisioning it to distributed firewall enforcement points, allowing selective policing of network communications among workloads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional hardware firewalls are used to control network traffic, then network security is provided, but the complexity of managing firewall rule sets increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall rule set management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a firewall rule generation system that acts as an intermediary between security policies and firewall enforcement. This system automatically generates, validates, and provisions firewall rules, eliminating the need for manual management of complex rule sets while maintaining security effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The firewall rule generation system performs self-service by automatically collecting information from external systems of record, generating appropriate firewall rules based on security policies, validating rule consistency, and provisioning rules to enforcement points without requiring manual intervention from security teams.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual management of firewall rules is performed, then security policies can be enforced, but the time and resources required to maintain tens of thousands of rules increase

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidtime to maintain firewall rules
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically performs all firewall rule management tasks including collection of security requirements, rule generation, validation, and provisioning without human intervention, eliminating the time loss associated with manual rule maintenance.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by proactively generating and validating firewall rules before they are enforced, ensuring security policies are ready for deployment without delays. It continuously monitors and updates rules in response to changing security requirements.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If detailed firewall rules are created for each network communication, then precise security control is achieved, but the number of rules becomes unmanageably large

Engineering Contradiction:
Improvesecurity control precisionVSAvoidnumber of firewall rules
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts the essential security requirements from detailed communication patterns and generates only the necessary firewall rules to enforce those requirements. It removes redundant and overlapping rules while maintaining precise security control through automated validation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the parameter of rule specificity by generating rules at the appropriate level of detail based on security policy requirements. It transforms overly granular communication controls into optimized rule sets that maintain security precision while reducing rule quantity through automated consolidation and validation.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If firewall rules are frequently updated to adapt to changing network conditions, then security remains effective, but system stability and consistency deteriorate

Engineering Contradiction:
Improvesecurity policy adaptabilityVSAvoidfirewall rule set stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system implements feedback mechanisms by continuously monitoring security requirements and network conditions, then automatically adjusting firewall rules in response. The validation component provides feedback on rule consistency and conflicts, ensuring stable rule set composition even as security policies evolve.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The firewall rule generation system is dynamic, automatically adapting to changing security requirements by regenerating rules based on updated policies. It maintains stability through automated validation that ensures consistency during transitions, allowing the system to evolve without manual intervention while preserving rule set integrity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10333986B2Conditional declarative policies
Publication Date: 2019.06.25 GRYPHO5 LLC
  • US10333986B2 patent drawing
  • US10333986B2 patent drawing
  • US10333986B2 patent drawing

AI summary

Methods, systems, and media for producing a firewall rule set are provided herein. Exemplary methods may include receiving a declarative policy associated with a computer network security policy; collecting information from at least one external system of record; generating a firewall rule set using the declarative policy and information, the firewall rule set including addresses to or from which network communications are permitted, denied, redirected or logged, the firewall rule set being at a lower level of abstraction than the declarative policy; and provisioning the firewall rule set to a plurality of enforcement points of a distributed firewall, the firewall selectively policing network communications among workloads using the firewall rule set.