Dynamic Firewall Policy Generation for Cloud Workload Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls in cloud computing environments struggle to dynamically manage network traffic effectively, often blocking legitimate traffic due to static IP address filtering and failing to detect and mitigate cybersecurity risks in real-time, leading to potential security breaches.

Innovation Solution

A system and method that continuously detects cybersecurity risks by inspecting workloads for cybersecurity objects, generating dynamic network traffic policies, and configuring firewalls to filter traffic based on risk severity, allowing or blocking specific traffic types, and initiating mitigation actions as needed, with the ability to update policies when risks are mitigated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static IP address filtering is used in firewalls, then network security is improved, but legitimate traffic is blocked due to IP changes over time

Engineering Contradiction:
Improvenetwork securityVSAvoidtraffic throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic firewall rule generation by continuously monitoring workload cybersecurity risks and automatically updating firewall configurations. Instead of static IP filtering, the system dynamically adjusts security rules based on real-time risk assessments, allowing the firewall to adapt to IP changes while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where cybersecurity risk detection continuously monitors workloads, feeds risk information back to the firewall configuration system, which then updates security rules accordingly. This closed-loop feedback mechanism ensures that firewall policies remain effective despite IP address changes.

Inventive Principle:
Principle #23Feedback

2Reliability

If firewall filtering is applied to manage network traffic, then security posture is improved, but false positives increase blocking legitimate traffic

Engineering Contradiction:
Improvesecurity postureVSAvoidtraffic management accuracy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the filtering parameters from static IP addresses to dynamic cybersecurity risk parameters. The firewall uses risk-based decision-making with multiple parameters including risk level, traffic type, and workload context to make more accurate filtering decisions, reducing false positives while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies differentiated security measures based on local risk characteristics. Instead of uniform filtering, the firewall adjusts its behavior according to the specific risk profile of each workload and traffic type, allowing legitimate traffic to pass while blocking only truly malicious traffic.

Inventive Principle:
Principle #3Local quality

3Reliability

If continuous cybersecurity risk detection is implemented, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions into an integrated system where risk detection, policy generation, and firewall configuration work together as a unified architecture. This consolidation reduces overall system complexity compared to separate security tools while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements self-service automation where the firewall configuration is automatically generated and updated based on risk detection outputs. This eliminates the need for manual security rule creation and reduces operational complexity while maintaining high security coverage.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If dynamic firewall policy updates are implemented, then adaptability to security threats is improved, but configuration management complexity increases

Engineering Contradiction:
Improvesecurity adaptabilityVSAvoidconfiguration management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system uses feedback from continuous risk detection to automatically trigger firewall policy updates. This closed-loop approach handles the complexity of dynamic configuration management by automating the entire process based on real-time security conditions, eliminating manual intervention requirements.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by proactively detecting cybersecurity risks before they manifest as attacks. By identifying and responding to risks early, the system can pre-configure firewall rules to prevent potential threats, simplifying reactive configuration management.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250097201A1Techniques for cybersecurity risk-based firewall configuration
Publication Date: 2025.03.20 WIZ INC
  • US20250097201A1 patent drawing
  • US20250097201A1 patent drawing
  • US20250097201A1 patent drawing

AI summary

A system and method for providing dynamic network traffic policies is provided. The method includes: inspecting a workload for a cybersecurity object, the cybersecurity object indicating a cybersecurity risk, wherein the workload is deployed in a cloud computing environment having a firewall connected to an external network; detecting the cybersecurity risk on the workload based on the cybersecurity object; generating a policy for the firewall based on the cybersecurity risk; and configuring the firewall to apply the generated policy.