DNS Agent Dynamic Firewall Rule Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional application firewall systems in cloud-based infrastructure are inefficient and time-consuming for initial configuration and continuous updates of security rules, particularly due to the lack of automation and uniformity in managing dynamic IP addresses, which disrupt normal operations.
Innovation Solution
A method and system that intercepts DNS query responses to decode network address information and automatically update security rules for application firewalls, allowing for dynamic reconfiguration without disrupting operations, using a DNS Agent to manage authorized and unauthorized addresses within the cloud-based infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual configuration of security rules is used for each application firewall, then security rules can be initially set up, but the process becomes inefficient and time-consuming, particularly for large organizations with thousands of applications
Solution Approach 1:
The system performs preliminary actions by automatically configuring security rules before applications need to operate. The DNS Agent intercepts DNS queries during the application startup phase and pre-configures the firewall security rules with the required IP addresses and port numbers, eliminating the need for manual post-configuration.
Solution Approach 2:
The application firewall system serves itself by automatically managing its own security rule configuration. The DNS Agent within the firewall intercepts DNS queries from applications, extracts the required network information, and automatically updates security rules without requiring manual intervention from administrators.
2Adaptability or versatility
If manual reconfiguration of security rules is used to update authorized network addresses, then security rules can be updated, but the application firewall must be restarted which disrupts normal operation
Solution Approach 1:
The system introduces dynamics by enabling real-time updates of security rules without requiring firewall restarts. The DNS Agent continuously monitors DNS queries and dynamically updates the firewall's security rule tables in memory, allowing the firewall to adapt to changing network conditions while maintaining continuous operation.
Solution Approach 2:
The system ensures continuity of useful action by maintaining continuous operation of the firewall during security rule updates. The DNS Agent performs updates in the background without interrupting the firewall's packet filtering function, ensuring that security protection continues uninterrupted throughout the reconfiguration process.
3Reliability
If conventional firewall systems are used, then security rules can be maintained, but there is no uniform way to share updated network information across firewalls in the cloud-based infrastructure
Solution Approach 1:
The system achieves universality by providing a standardized mechanism that works across all firewalls in the cloud-based infrastructure. The DNS Agent uses the universal DNS query protocol to extract network information and distribute it uniformly to all relevant firewalls, eliminating the need for firewall-specific configuration methods.
Solution Approach 2:
The system implements feedback by having the DNS Agent continuously monitor DNS queries and automatically propagate updated network information to firewalls. This feedback loop ensures that all firewalls receive the most current network information in a uniform manner, maintaining consistency across the entire infrastructure.
Data Source
AI summary
The invention relates to a computer-implemented system and method for efficiently configuring the security rules for application firewalls in a cloud-based infrastructure, the cloud-based infrastructure containing at least one of a virtual machine comprising an application, a Domain Name System (DNS) Agent, and a firewall. The method may comprise requesting, by the application, network address information via a DNS server for a fully qualified domain name (FQDN); intercepting, by the DNS Agent, data packets containing the DNS Server query response; decoding, by the DNS Agent, the DNS query response, and identifying the network address information; and updating a security rule of the firewall, by the DNS Agent, based on the decoded network address information. The method may be implemented to update the security rules of application firewalls across an organization's cloud-based infrastructure.


