Automated Firewall ACL Rule Generation Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current manual configuration of Access Control Lists (ACLs) for firewalls in data centers is time-consuming, error-prone, and requires extensive knowledge of diverse vendor hardware and syntax, especially in large and complex environments like healthcare data centers, where continuous updates and audits are necessary.

Innovation Solution

A vendor-agnostic computing platform automatically generates and deploys ACL rules in multiple syntaxes for firewalls, using intelligent discovery modules to identify firewalls and traverse data center mapping structures, thereby simplifying the configuration process and reducing manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual configuration of ACL rules is performed, then flexibility and adaptability are maintained, but time consumption and error rates increase significantly

Engineering Contradiction:
Improveconfiguration speedVSAvoidconfiguration accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs self-service by automatically discovering firewalls, generating ACL rules, and deploying configurations without manual intervention. The automated discovery module identifies firewalls and their syntax requirements, while the generation module creates appropriate ACL rules based on source and destination IP addresses, eliminating manual configuration errors and time consumption.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual configuration process with an automated computational system. The discovery module, generation module, and deployment module work together to substitute human operators with an automated system that handles firewall configuration tasks, improving both speed and consistency of operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual testing and validation of ACL rules is performed, then accuracy can be verified, but time consumption increases

Engineering Contradiction:
Improverule validation accuracyVSAvoidtesting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system incorporates feedback mechanisms where the discovery module continuously monitors the network environment to identify firewalls and their syntax requirements. The generation module uses this feedback to create appropriately formatted ACL rules, and the deployment module validates the configuration deployment, creating a closed-loop feedback system that ensures accuracy without requiring manual testing.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If knowledge of multiple vendor hardware and syntax is required, then comprehensive coverage is achieved, but operational complexity increases

Engineering Contradiction:
Improvevendor compatibilityVSAvoidconfiguration simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system achieves universality by implementing a unified automated platform that handles multiple vendor firewalls with different syntax requirements. The discovery module identifies the specific vendor and syntax for each firewall, while the generation module adapts the ACL rules to match the required syntax, allowing a single system to manage diverse vendor equipment without requiring operators to know each vendor's specific configuration format.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11811736B2Generating network infastructure firewalls
Publication Date: 2023.11.07 CERNER INNOVATION INC
  • US11811736B2 patent drawing
  • US11811736B2 patent drawing
  • US11811736B2 patent drawing

AI summary

Systems, methods, and storage media useful in a computing platform to automatically generate and deploy access control list (ACL) rules for one or more firewalls in a data center are provided. The computing platform is vendor-agnostic and generates ACL rules in multiple syntaxes depending on the firewall needing updating. The platform traverses a data center mapping structure to identify one or more firewalls to be updated for a destination IP address and source IP address and automatically generates the ACL rule in the syntax for the one or more firewalls identified.