Filtering Rule Mapping for Diverse Network Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing filtering rule setting support methods struggle to effectively manage and analyze filtering rules across diverse types of filter devices in large-scale intranets, as they assume a uniform interface and description method for collecting and analyzing rules, which is not feasible in practice.
Innovation Solution
A filtering setting support device and method that includes a logical/physical mapping unit to generate mapping information, a filtering point analysis unit to identify nodes where multiple flows intermingle, and a common format rule generation unit to create and present rules suitable for each filtering point, independent of the target device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central filtering rule management device collects and analyzes filtering rules from diverse filter devices, then filtering rule consistency and redundancy can be detected, but the system cannot handle devices with different interfaces and description methods
Solution Approach 1:
The patent introduces a common format as an intermediary representation layer between diverse filter devices and the central management device. Filtering rules from different devices are converted to this common format, enabling uniform analysis while maintaining compatibility with various device interfaces and description methods.
Solution Approach 2:
The patent transforms filtering rules by changing their representation parameters - converting device-specific rule formats into a standardized common format. This parameter transformation enables the central management device to analyze rules from diverse sources using统一的 criteria while preserving the original device compatibility.
2Adaptability or versatility
If filtering rules are individually set to each filter device in a large-scale intranet, then device-specific requirements can be met, but the filtering rules become dispersed and improper settings occur
Solution Approach 1:
The patent implements a feedback mechanism where the central filtering rule management device analyzes rules from all filter devices, detects inconsistencies and redundancies, and provides feedback to network administrators for correction. This closed-loop approach maintains device-specific configurations while ensuring overall consistency through centralized monitoring and adjustment.
Solution Approach 2:
The patent creates a universal common format that can represent filtering rules from multiple different device types and vendors. This universal representation enables the central management device to perform multiple functions - collecting, analyzing, and managing rules across diverse filter devices while maintaining their individual characteristics.
3Extent of automation
If existing filtering rule setting support methods are applied, then rule collection and analysis can be performed, but they fail when devices have different interfaces and description methods
Solution Approach 1:
The common format acts as an intermediary that enables automatic rule collection from diverse devices. By converting device-specific rules to this intermediate representation, the system achieves automation while maintaining compatibility with various device interfaces and description methods.
Solution Approach 2:
The patent segments the rule management process into distinct stages: collection from devices in various formats, conversion to common format, centralized analysis, and feedback generation. This segmentation allows each stage to handle device diversity appropriately while maintaining overall automation.
Data Source
AI summary
In a filtering setting support device, a logical/physical mapping section generates mapping information that represents a path on the layout of a network by a combination of start nodes and end nodes, the path being, for each flow identifier, from a transmission source node to a destination node, based on node physical layout information and access policy information. The access policy information manages flow information including a combination of transmission source node and destination node, by attaching a flow identifier. A filtering point analysis section specifies as a filtering point a node where a plurality of flows are co-present. A common formal rule generating section generates common formal rules that are to be set at the filtering point. A common formal rule output section presents common formal rules to a network administrator.


