Firewall Access Control Using BGP Attributes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current firewall policies are inefficient for larger scale security policies, particularly at autonomous system boundaries, as they require significant administrative overhead to maintain dynamic IP protocol-level security rules, which are not effectively managed by existing methods.
Innovation Solution
Implementing firewall access control using Border Gateway Protocol (BGP) attributes, where packets are routed and firewall policies are applied based on BGP attributes associated with IP addresses, reducing administrative burdens and enhancing policy definition.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewall policies are implemented by manually specifying external IP address blocks, then access control can be applied, but significant administrative overhead is required to maintain dynamic IP protocol-level security rules
Solution Approach 1:
The patent introduces BGP attributes as an intermediary layer between routing decisions and firewall policy enforcement. Instead of directly managing IP address blocks, the system uses BGP community attributes and AS path attributes to represent groups of IP addresses, allowing firewall rules to reference these attributes rather than individual IP ranges. This intermediary representation reduces administrative overhead while maintaining security effectiveness.
Solution Approach 2:
The patent makes the firewall device multi-functional by combining routing functionality (BGP speaker) with firewall policy enforcement in a single device. The firewall can simultaneously perform routing decisions based on BGP attributes and apply security policies based on the same attributes, eliminating the need for separate manual IP address block management and reducing operational complexity.
2Measurement precision
If firewall policies are applied at IP protocol level for each individual IP address, then precise security control is achieved, but the complexity of managing dynamic IP ranges increases significantly
Solution Approach 1:
The patent segments the large set of IP addresses into groups represented by BGP attributes (community attributes and AS path attributes). Instead of managing individual IP address rules, the system creates firewall policies that reference these attribute-based segments. This segmentation maintains precision in security control while dramatically reducing the number of rules needed to manage dynamic IP ranges.
Solution Approach 2:
The patent changes the parameter basis for firewall rules from specific IP address values to BGP attribute parameters (community strings and AS path sequences). This parameter transformation allows the firewall to maintain precise control over security decisions while adapting automatically to routing changes without requiring manual updates to IP address blocks, thereby reducing policy management complexity.
Data Source
AI summary
Packets are routed from at least one internet protocol (IP) address in accordance with border gateway protocol (BGP); while carrying out the routing in accordance with the border gateway protocol (BGP), at least one border gateway protocol (BGP) attribute associated with the at least one internet protocol (IP) address is noted. A firewall policy is applied to the packets from the at least one internet protocol (IP) address based on the at least one border gateway protocol (BGP) attribute associated with the at least one internet protocol (IP) address. Techniques may be implemented, for example, on a router or on a separate firewall device coupled to a router.


