Firewall Policy Inspection Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall policy inspection technologies fail to efficiently detect and display anomaly rules, such as shadowing, redundancy, correlation, and generalization anomalies, between intrusion prevention rules, and do not indicate risk levels effectively, leading to increased effort and potential security vulnerabilities.

Innovation Solution

A firewall policy inspection apparatus and method that includes an intrusion prevention rule obtainment unit, an anomaly rule detection unit, and a screen display unit to detect and display anomaly rules in relationships between intrusion prevention rules, indicating them in colors based on risk levels, allowing for easier inspection of firewall policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual detection of anomaly rules is performed by a manager, then detection capability is maintained, but effort and time requirements increase significantly

Engineering Contradiction:
Improveanomaly rule detection capabilityVSAvoidtime required for manual inspection
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces the manual mechanical inspection process with an automated computer-based system that uses algorithms to detect anomaly rules. The anomaly rule detection unit automatically analyzes firewall policies and identifies shadowing, redundancy, correlation, and generalization anomalies without human intervention, thereby eliminating the time-consuming manual inspection while maintaining detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service by allowing the firewall policy inspection to be performed automatically by the computer itself rather than requiring external human management. The anomaly detection unit continuously monitors and inspects rules autonomously, freeing managers from the burden of manual detection while ensuring consistent and reliable anomaly identification.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If manual detection of anomaly rules is performed by a manager, then detection capability is maintained, but error rates increase due to human factors

Engineering Contradiction:
Improveanomaly rule detection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent eliminates human error by replacing manual detection with an automated computer-based anomaly detection unit. This system applies consistent algorithmic logic to identify shadowing, redundancy, correlation, and generalization anomalies, ensuring reliable and accurate detection without the variability and errors inherent in human inspection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system incorporates feedback mechanisms where the anomaly detection unit continuously analyzes firewall policies and provides structured output about detected anomalies. This automated feedback loop ensures consistent application of detection rules and maintains high reliability by systematically identifying and reporting anomaly patterns without human intervention.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If conventional inspection methods are used, then existing functionality is maintained, but anomaly rules cannot be effectively detected among multiple intrusion prevention rules

Engineering Contradiction:
Improvefirewall policy inspection functionalityVSAvoidanomaly rule detection among multiple rules
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the complex task of firewall policy inspection into distinct anomaly types: shadowing anomalies, redundancy anomalies, correlation anomalies, and generalization anomalies. Each type is detected by specific detection logic within the anomaly detection unit, making the overall complex inspection process manageable and effective by breaking it down into targeted detection segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of inspection by analyzing relationships between multiple intrusion prevention rules simultaneously. Rather than examining rules in isolation, the system evaluates inter-rule relationships to detect anomalies, adding a relational dimension to the inspection process that enables effective detection among multiple rules.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Measurement precision

If detailed anomaly detection is implemented, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveanomaly rule detection accuracyVSAvoidinspection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent manages complexity by segmenting anomaly detection into four distinct anomaly types with specific detection logic for each. This segmentation allows the system to achieve high detection accuracy through specialized algorithms for each anomaly type while organizing the overall system structure in a manageable, modular way that reduces operational complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9083678B2Firewall policy inspection apparatus and method
Publication Date: 2015.07.14 ELECTRONICS & TELECOMM RES INST
  • US9083678B2 patent drawing
  • US9083678B2 patent drawing
  • US9083678B2 patent drawing

AI summary

A firewall policy inspection apparatus and method is provided. The firewall policy inspection apparatus includes an intrusion prevention rule obtainment unit for obtaining intrusion prevention rules from a target firewall policy. An anomaly rule detection unit detects an anomaly rule in a relationship between the intrusion prevention rules. A screen display unit displays an anomaly rule graph on a screen using results of the detection.