DNS Agent Dynamic Firewall Rule Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional application firewall systems in cloud-based infrastructure are inefficient and time-consuming for initial configuration and continuous updates of security rules, particularly due to the lack of automation and uniformity in managing dynamic IP addresses, which disrupt normal operations.

Innovation Solution

A method and system that intercepts DNS query responses to decode network address information and automatically update security rules for application firewalls, allowing for dynamic reconfiguration without disrupting operations, using a DNS Agent to manage authorized and unauthorized addresses within the cloud-based infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual configuration of security rules is used for each application firewall, then security rules can be initially set up, but the process becomes inefficient and time-consuming, particularly for large organizations with thousands of applications

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidtime required for initial configuration
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically configuring security rules before applications need to operate. The DNS Agent intercepts DNS queries during the application startup phase and pre-configures the firewall security rules with the required IP addresses and port numbers, eliminating the need for manual post-configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The application firewall system serves itself by automatically managing its own security rule configuration. The DNS Agent within the firewall intercepts DNS queries from applications, extracts the required network information, and automatically updates security rules without requiring manual intervention from administrators.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If manual reconfiguration of security rules is used to update authorized network addresses, then security rules can be updated, but the application firewall must be restarted which disrupts normal operation

Engineering Contradiction:
Improveability to update network informationVSAvoidcontinuous operation of firewall
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system introduces dynamics by enabling real-time updates of security rules without requiring firewall restarts. The DNS Agent continuously monitors DNS queries and dynamically updates the firewall's security rule tables in memory, allowing the firewall to adapt to changing network conditions while maintaining continuous operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system ensures continuity of useful action by maintaining continuous operation of the firewall during security rule updates. The DNS Agent performs updates in the background without interrupting the firewall's packet filtering function, ensuring that security protection continues uninterrupted throughout the reconfiguration process.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If conventional firewall systems are used, then security rules can be maintained, but there is no uniform way to share updated network information across firewalls in the cloud-based infrastructure

Engineering Contradiction:
Improvesecurity rule maintenanceVSAvoiduniformity of network information sharing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system achieves universality by providing a standardized mechanism that works across all firewalls in the cloud-based infrastructure. The DNS Agent uses the universal DNS query protocol to extract network information and distribute it uniformly to all relevant firewalls, eliminating the need for firewall-specific configuration methods.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback by having the DNS Agent continuously monitor DNS queries and automatically propagate updated network information to firewalls. This feedback loop ensures that all firewalls receive the most current network information in a uniform manner, maintaining consistency across the entire infrastructure.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11159488B2Dynamic application firewalling in cloud systems
Publication Date: 2021.10.26 JPMORGAN CHASE BANK NA
  • US11159488B2 patent drawing
  • US11159488B2 patent drawing
  • US11159488B2 patent drawing

AI summary

The invention relates to a computer-implemented system and method for efficiently configuring the security rules for application firewalls in a cloud-based infrastructure, the cloud-based infrastructure containing at least one of a virtual machine comprising an application, a Domain Name System (DNS) Agent, and a firewall. The method may comprise requesting, by the application, network address information via a DNS server for a fully qualified domain name (FQDN); intercepting, by the DNS Agent, data packets containing the DNS Server query response; decoding, by the DNS Agent, the DNS query response, and identifying the network address information; and updating a security rule of the firewall, by the DNS Agent, based on the decoded network address information. The method may be implemented to update the security rules of application firewalls across an organization's cloud-based infrastructure.