Dynamic Attribute-Based Firewall Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualized computing environments pose challenges for firewall rules that rely on static information, such as static IP addresses, as they are dynamic and can lead to difficulties in managing and enforcing policies effectively.

Innovation Solution

A data appliance with a tag repository and agent infrastructure that dynamically collects and updates virtual machine information, allowing for the creation of address groups based on match criteria, enabling policies to be applied to virtual machines without requiring manual updates of specific IP addresses, and automatically recompiling rules as virtual machine states change.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static IP addresses are used for firewall rules, then policy enforcement is simple and stable, but adaptability to dynamic virtualized environments deteriorates

Engineering Contradiction:
Improvepolicy enforcement stabilityVSAvoidadaptability to dynamic virtual machines
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by transitioning from static IP address-based firewall rules to dynamic attribute-based matching. Virtual machine attributes such as OS type, application running, and other characteristics are continuously monitored and used to dynamically update firewall rule matching, enabling the system to adapt to changing virtualized environments while maintaining policy enforcement stability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters used for firewall rule matching from fixed IP addresses to dynamic attributes of virtual machines. By monitoring changes in virtual machine attributes (operating system, applications, configurations) and automatically updating firewall rules based on these parameter changes, the system achieves both reliability and adaptability

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If manual updates of IP addresses are performed, then firewall rules remain accurate, but loss of time and productivity deteriorates

Engineering Contradiction:
Improvefirewall rule accuracyVSAvoidtime for manual updates
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the firewall rule management system to automatically detect changes in virtual machine attributes and self-update firewall rules without human intervention. The system continuously monitors virtual machine states and automatically recompiles and applies updated firewall rules, eliminating the need for manual IP address updates while maintaining high accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs feedback mechanisms where the system continuously monitors virtual machine attribute changes and feeds this information back to the firewall rule management system. This feedback loop enables automatic detection of changes and triggers corresponding rule updates, ensuring firewall rules remain accurate without requiring manual intervention

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If dynamic attribute-based matching is implemented, then adaptability to virtualized environments improves, but device complexity increases

Engineering Contradiction:
Improveadaptability to virtual machine dynamicsVSAvoidcomplexity of policy management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a multi-functional policy management system that handles attribute collection, change detection, rule compilation, and firewall enforcement through a single integrated architecture. This universal system can manage multiple virtual machines with different attributes using the same framework, reducing the perceived complexity despite the enhanced adaptability

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If virtual machines are frequently spun up and down, then productivity and flexibility improve, but reliability of firewall policy enforcement deteriorates

Engineering Contradiction:
Improvevirtual machine provisioning speedVSAvoidfirewall rule consistency
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring firewall rules based on virtual machine attributes rather than requiring rules to be manually created for each virtual machine instance. When virtual machines are spun up or down, the system automatically detects attribute changes and applies appropriate firewall rules, ensuring consistent policy enforcement regardless of provisioning frequency

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10348765B2Policy enforcement based on dynamically attribute-based matched network objects
Publication Date: 2019.07.09 PALO ALTO NETWORKS INC
  • US10348765B2 patent drawing
  • US10348765B2 patent drawing
  • US10348765B2 patent drawing

AI summary

A policy that includes an address group is received. The policy is compiled into a set of one or more rules. The compiling is performed at least in part by determining members of the address group. The compiling can further include substituting one or more IP addresses of the members for the address group. At least one rule included in the set of rules is enforced.