Dynamic Network Object for Firewall Protection of Dynamic Routes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Dynamic routing in internal communication networks introduces unpredictable routes that are not configurable under existing firewall security policies, leading to a loss of control for system administrators and increased security concerns.

Innovation Solution

A system comprising a route collection engine and a firewall engine dynamically learns and tags routes, creating a dynamic network object to apply granular security policies through IP address matching, enabling the enforcement of security measures on dynamically introduced routes under various routing protocols like OSPF, BGP, and RIP.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dynamic routing protocols are used to enable flexible route selection, then network adaptability and failover capability are improved, but security control and firewall policy enforcement deteriorate

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a dynamic network object as an intermediary between the dynamic routing service and the firewall engine. This object collects and stores IP addresses from dynamically introduced routes, enabling the firewall to apply security policies to these routes without compromising the dynamic routing functionality. The intermediary bridges the gap between routing flexibility and security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by proactively collecting IP addresses from dynamic routes and storing them in a dynamic network object before firewall policy evaluation is needed. This allows the firewall engine to have advance knowledge of dynamically introduced routes and apply appropriate security policies, rather than reacting after security concerns arise.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If firewall rules are configured to enforce security policies, then security protection is improved, but configurability and ease of management for dynamic routes deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfigurability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamics by creating a dynamic network object that automatically updates with IP addresses from dynamically introduced routes. Instead of requiring manual configuration updates when routes change, the system dynamically adapts the network object content, maintaining security policy enforceability without burdening administrators with manual reconfiguration tasks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The dynamic network object performs self-service by automatically collecting IP addresses from the dynamic routing service and updating itself as routes are introduced or removed. This eliminates the need for system administrators to manually track and update firewall configurations for dynamic routes, significantly reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual route tracking is implemented to maintain security control, then security monitoring is improved, but system complexity and administrative burden increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The dynamic network object serves multiple functions: it collects IP addresses from dynamic routes, stores them for firewall reference, and automatically updates as routes change. This multi-functional component consolidates what would otherwise require separate manual tracking systems, reducing overall system complexity while maintaining comprehensive security monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11588724B2System and method for firewall protection of dynamically introduced routes
Publication Date: 2023.02.21 BARRACUDA NETWORKS INC
  • US11588724B2 patent drawing
  • US11588724B2 patent drawing
  • US11588724B2 patent drawing

AI summary

A new approach is proposed to support firewall protection of dynamically introduced routes in an internal communication network. Under the proposed approach, all routes dynamically introduced into the internal communication network via a dynamic routing service are dynamically learned and tagged by a route collection engine. A dynamic network object is created, which is a software component configured to store a plurality of single IP addresses and/or IP address ranges of the dynamically learned routes in a dynamic routing network. A firewall engine of the internal communication network is configured to create one or more firewall rules referencing the dynamic network object and apply various security measures/policies to network data packets routed on the dynamically learned routes in the dynamic routing network based on IP address matching with the dynamic network object.