Firewall Engine Provisioning via Observation Mode

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-based hosting environments with network micro-segmentation, provisioning firewall engines for multiple application instances across different zones is challenging due to the need for customized firewall rules to manage unique network traffic patterns.

Innovation Solution

A system and method that involves implementing firewall engines in an observation mode, where predefined rules are applied, network traffic events are logged, grouped, and new firewall rules are generated based on these events, and then accepted or denied using machine learning or input devices, before switching to a maintain mode where the new rules replace the predefined rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If predefined firewall rules are applied in observation mode to manage network traffic, then network security is maintained, but the customization of firewall rules for specific zones is delayed

Engineering Contradiction:
Improvenetwork securityVSAvoidtime for rule customization
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by implementing predefined firewall rules in observation mode before full customization is complete. This allows the firewall to start protecting network traffic immediately while the customized rules are being generated and approved, resolving the contradiction between maintaining security and enabling customization timing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The firewall engine transitions dynamically between observation mode and maintain mode. In observation mode, predefined rules are applied with logging enabled. Once customized rules are generated and approved, the system dynamically switches to maintain mode where the customized rules replace predefined rules. This dynamic transition resolves the contradiction by allowing both security maintenance and rule customization to occur at appropriate times.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If firewall engines are provisioned for each application instance in micro-segmentation environments, then network traffic management precision is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork traffic management precisionVSAvoidfirewall provisioning complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The firewall engine is designed with multi-functionality to operate in both observation mode and maintain mode, and to handle both predefined rules and customized rules. This universal design allows a single firewall engine to serve multiple application instances in micro-segmentation environments without requiring separate provisioning processes for each instance, thus improving traffic management precision while managing complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service by automatically generating customized firewall rules based on observed network traffic patterns. The firewall engine monitors traffic in observation mode, automatically creates customized rules from the observed patterns, and enables these rules after approval. This automation eliminates the need for manual provisioning of each firewall instance, reducing complexity while maintaining precise traffic management for multiple application instances.

Inventive Principle:
Principle #25Self-service

3Manufacturing precision

If network traffic events are logged and grouped to generate new firewall rules, then rule accuracy is improved, but processing time increases

Engineering Contradiction:
Improvefirewall rule accuracyVSAvoidrule generation time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs preliminary logging of network traffic events during observation mode before rule generation is required. By continuously logging traffic patterns in advance, the system accumulates sufficient data to generate accurate customized rules when needed, without rushing the rule generation process. This preliminary data collection improves rule accuracy while allowing adequate time for analysis and generation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary approval step between rule generation and rule implementation. Customized rules are generated based on logged traffic patterns, then presented for approval before being implemented. This intermediary step allows thorough analysis of generated rules, ensuring high accuracy while providing a controlled timeline that balances processing time with rule quality. The approval mechanism acts as a mediator that validates rule accuracy without creating unnecessary delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12143364B2Device, system, and method for provisioning firewall engines
Publication Date: 2024.11.12 MOTOROLA SOLUTIONS INC
  • US12143364B2 patent drawing
  • US12143364B2 patent drawing
  • US12143364B2 patent drawing

AI summary

A device, system and method for provisioning firewall engines is provided. A device, in an observation mode: implements, for a given zone, an application and a firewall engine in an observation mode by: implementing predefined firewall rules that define allowed network traffic and/or denied network traffic for the application; maintaining a log of network traffic events that meet or do not meet the predefined firewall rules, the log including source and destination network identifiers for the network traffic events; grouping the network traffic events into groups based on the source and destination network identifiers; generating new firewall rules based on the groups; and accepting or denying respective new firewall rules. The device, after the observation mode is implemented, switches the application and the firewall engine to a maintain mode by: stopping implementing the predefined firewall rules; and implementing accepted new firewall rules for the application.