Centralized Firewall Block List Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing firewall configurations across multiple networks is challenging due to the complexity of manually updating block lists and the risk of erroneous or redundant entries, especially in cloud computing environments where numerous firewalls are deployed.

Innovation Solution

A system and method for dynamically generating block lists within a client instance, allowing users to request block or allow actions on observables, which are then validated and approved, and centrally managed to ensure agile and consistent responses to emerging threats across multiple client firewalls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual updating of block lists is performed across multiple firewalls, then flexibility in individual firewall management is maintained, but the complexity of configuration management increases significantly

Engineering Contradiction:
Improvefirewall configuration managementVSAvoidconfiguration management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the configuration management of multiple firewalls into a centralized system. A single block list configuration performed at one location is automatically distributed to and applied across all firewalls in the network, eliminating the need for manual updating of each firewall individually and significantly reducing configuration management complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized block list system serves multiple firewalls simultaneously with a single configuration. The system provides universal management capabilities that can handle numerous firewalls across different networks, allowing one configuration instance to manage multiple firewalls rather than requiring separate management for each.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If block lists are manually configured and updated, then control over individual firewall rules is maintained, but the risk of erroneous or redundant entries increases

Engineering Contradiction:
Improveblock list accuracyVSAvoidmanual configuration control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements feedback mechanisms where block list configurations are automatically validated before being applied to firewalls. The centralized system monitors and tracks block list entries across all firewalls, providing feedback on potential errors or redundancies and preventing incorrect configurations from being deployed.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system provides self-service capabilities through automated validation and error detection mechanisms. The centralized configuration system automatically checks for erroneous or redundant block list entries before deployment, reducing reliance on manual verification and minimizing the risk of configuration errors.

Inventive Principle:
Principle #25Self-service

3Stability of the object's composition

If centralized block list management is implemented, then consistency across multiple firewalls is improved, but the system complexity increases

Engineering Contradiction:
Improveblock list consistencyVSAvoidcentralized management system complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The centralized management system is segmented into distinct functional modules: configuration input, validation, distribution, and monitoring. This segmentation allows each component to perform its specific function independently, reducing overall system complexity while maintaining consistency across firewalls. The block list management is separated from firewall operation, allowing independent optimization of each function.

Inventive Principle:
Principle #1Segmentation

4Speed

If dynamic generation of block lists is implemented, then response time to emerging threats is reduced, but the automation complexity increases

Engineering Contradiction:
Improvethreat response timeVSAvoidautomation system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring the centralized block list management infrastructure and establishing automated validation rules in advance. When threats emerge, the system can immediately generate and distribute block list updates without requiring complex real-time analysis or manual intervention, reducing response time while keeping automation complexity manageable.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10708230B2Systems and methods for firewall configuration using block lists
Publication Date: 2020.07.07 SERVICENOW INC
  • US10708230B2 patent drawing
  • US10708230B2 patent drawing
  • US10708230B2 patent drawing

AI summary

The present disclosure relates generally to firewall configuration management, and, more specifically, to managing firewall configurations using dynamically generated block lists. A computer-implemented method includes adding an entry as a record in a block list entries table and associating the entry with a block list in a block list table and with an observable in an observables table. The method also includes activating the entry in the block list entries table to allow or block subsequent occurrences of the observable on a client network. The method further includes receiving a request for the block list from a firewall disposed on the client network and, in response, generating the block list from activated entries in the block list table and block list entries table and sending the block list to the firewall, wherein the firewall is configured to allow or block network traffic associated with the observable on the client network in accordance with the block list.