Dynamic Attribute-Based Firewall Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtualized computing environments pose challenges for firewall rules that rely on static information, such as static IP addresses, as they are dynamic and can lead to difficulties in managing and enforcing policies effectively.
Innovation Solution
A data appliance with a tag repository and agent infrastructure that dynamically collects and updates virtual machine information, allowing for the creation of address groups based on match criteria, enabling policies to be applied to virtual machines without requiring manual updates of specific IP addresses, and automatically recompiling rules as virtual machine states change.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static IP addresses are used for firewall rules, then policy enforcement is simple and stable, but adaptability to dynamic virtualized environments deteriorates
Solution Approach 1:
The patent applies dynamics by transitioning from static IP address-based firewall rules to dynamic attribute-based matching. Virtual machine attributes such as OS type, application running, and other characteristics are continuously monitored and used to dynamically update firewall rule matching, enabling the system to adapt to changing virtualized environments while maintaining policy enforcement stability
Solution Approach 2:
The patent changes the parameters used for firewall rule matching from fixed IP addresses to dynamic attributes of virtual machines. By monitoring changes in virtual machine attributes (operating system, applications, configurations) and automatically updating firewall rules based on these parameter changes, the system achieves both reliability and adaptability
2Measurement precision
If manual updates of IP addresses are performed, then firewall rules remain accurate, but loss of time and productivity deteriorates
Solution Approach 1:
The patent implements self-service by enabling the firewall rule management system to automatically detect changes in virtual machine attributes and self-update firewall rules without human intervention. The system continuously monitors virtual machine states and automatically recompiles and applies updated firewall rules, eliminating the need for manual IP address updates while maintaining high accuracy
Solution Approach 2:
The patent employs feedback mechanisms where the system continuously monitors virtual machine attribute changes and feeds this information back to the firewall rule management system. This feedback loop enables automatic detection of changes and triggers corresponding rule updates, ensuring firewall rules remain accurate without requiring manual intervention
3Adaptability or versatility
If dynamic attribute-based matching is implemented, then adaptability to virtualized environments improves, but device complexity increases
Solution Approach 1:
The patent applies universality by creating a multi-functional policy management system that handles attribute collection, change detection, rule compilation, and firewall enforcement through a single integrated architecture. This universal system can manage multiple virtual machines with different attributes using the same framework, reducing the perceived complexity despite the enhanced adaptability
4Productivity
If virtual machines are frequently spun up and down, then productivity and flexibility improve, but reliability of firewall policy enforcement deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-configuring firewall rules based on virtual machine attributes rather than requiring rules to be manually created for each virtual machine instance. When virtual machines are spun up or down, the system automatically detects attribute changes and applies appropriate firewall rules, ensuring consistent policy enforcement regardless of provisioning frequency
Data Source
AI summary
A policy that includes an address group is received. The policy is compiled into a set of one or more rules. The compiling is performed at least in part by determining members of the address group. The compiling can further include substituting one or more IP addresses of the members for the address group. At least one rule included in the set of rules is enforced.


