Dynamic Firewall Policy Management via PEP and PDP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current firewalls are inflexible and ineffective in public networks, as they often require users to initiate connections through specific application proxies, restrict access to specific applications, and do not adequately manage trust between users and network components, leading to unsatisfactory user experiences and security vulnerabilities.
Innovation Solution
The implementation of a policy enforcement point (PEP) and policy decision point (PDP) system that allows nodes to send their preferences or options to manage firewall configurations dynamically, enabling flexible communication and improved network protection by authenticating and authorizing requests using protocols like FCON, which allows for secure and adaptable firewall management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewall configurations are used, then network security is maintained, but user flexibility and adaptability are reduced
Solution Approach 1:
The firewall system transitions from static administrator-configured rules to dynamic user-requested policies. The PEP and PDP enable real-time modification of firewall configurations based on user needs, allowing the system to adapt dynamically while maintaining security through authenticated policy requests.
Solution Approach 2:
Users can directly request and obtain their own firewall policy configurations without administrator intervention. The system enables users to self-serve by submitting policy requests through the FCON protocol and receiving automated approvals or rejections based on pre-configured security rules.
2Ease of operation
If firewall rules restrict access to specific applications, then network security is improved, but user convenience and ease of operation deteriorate
Solution Approach 1:
The system implements a feedback loop where users request policy changes, the PDP evaluates requests against security rules, and automatic decisions are communicated back to users. This automated feedback mechanism maintains security controls while improving user convenience by eliminating manual administrator intervention for routine requests.
3Device complexity
If firewall configurations are set by administrators, then centralized control is maintained, but system complexity and difficulty of management increase
Solution Approach 1:
The firewall management system is segmented into distinct functional components: PEP for policy enforcement, PDP for policy decisions, and separate authentication mechanisms. This segmentation distributes complexity across multiple specialized modules, making the overall system more manageable and easier to automate while maintaining centralized security control.
Data Source
AI summary
An apparatus comprising a policy enforcement point (PEP) configured to enforce firewall policies in a network, and a policy decision point (PDP) coupled to the PEP and configured to manage the PEP based on at least one firewall policy option received from at least one node. Also disclosed is a network component comprising at least one processor configured to implement a method comprising receiving a request from a node regarding a firewall policy entry, authenticating the node, processing the request to manage a firewall using a firewall control protocol, and sending a reply to the node regarding processing the request. Also disclosed is a method comprising signaling a PDP to establish a session associated with a source address and a requested protocol, and receiving an indication when the session is allowed.


