Unified Firewall Policy Management via Abstraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network and application security management systems face challenges in efficiently monitoring and managing security policies across multiple data centers, particularly due to the diversity in firewall architectures and protocols, which complicates unified management and configuration across different vendor platforms.

Innovation Solution

A security policy management system that includes a processor and memory, enabling unified management of multiple application devices by displaying them in a single pane view, abstracting rule bases, generating trend graphs for configuration changes, and applying logic to match and overlap IP address ranges for policy management, while allowing role-based access and metadata addition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unified management of multiple vendor firewall platforms is implemented, then ease of operation is improved, but device complexity increases due to diverse firewall architectures and protocols

Engineering Contradiction:
Improveunified management capabilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a centralized management platform that acts as an intermediary between administrators and multiple vendor-specific firewall devices. This platform provides a unified interface for managing diverse firewall architectures, translating administrator requests into vendor-specific configurations, and thereby simplifying operations while handling the underlying complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The management platform is designed with universal capabilities to handle multiple vendor platforms through a single system. It implements multi-functional interfaces that can adapt to different firewall architectures and protocols, enabling unified management across heterogeneous environments without requiring separate management tools for each vendor.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If abstracted rule base is implemented to display configurations of different vendors in unified manner, then ease of operation is improved, but loss of information increases due to abstraction layer

Engineering Contradiction:
Improveunified configuration displayVSAvoidvendor-specific configuration details
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements an abstracted rule base that adds a new dimensional layer for viewing firewall configurations. This abstraction layer presents vendor-specific configurations in a unified, vendor-agnostic format, allowing administrators to manage rules consistently across different platforms while the underlying system maintains the specific vendor details when needed.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If continuous monitoring of application specific objects is implemented, then measurement precision is improved, but use of energy increases due to continuous processing

Engineering Contradiction:
Improveconfiguration change detection accuracyVSAvoidprocessing energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system implements continuous monitoring of application-specific objects with feedback mechanisms that track configuration changes. The monitoring process provides precise detection of modifications by comparing current states against baseline configurations, enabling accurate change detection while the feedback loop allows the system to adapt its monitoring intensity based on detected changes.

Inventive Principle:
Principle #23Feedback

4Productivity

If logic is applied to match and overlap IP address ranges across multiple devices, then productivity is improved, but device complexity increases due to network logic processing

Engineering Contradiction:
Improvepolicy management efficiencyVSAvoidnetwork logic processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary processing of IP address ranges by pre-calculating overlaps and matches between address ranges before policy application. This preliminary action organizes the network logic processing in advance, enabling efficient policy management across multiple devices by having the complexity resolved beforehand rather than during runtime operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10645122B2System for monitoring and managing firewall devices and firewall management platforms
Publication Date: 2020.05.05 APPVIEWX INC
  • US10645122B2 patent drawing
  • US10645122B2 patent drawing
  • US10645122B2 patent drawing

AI summary

A computer implemented method for monitoring and managing a security policy of a plurality of application specific objects across a plurality of datacenters are provides. The computer implemented method includes following steps: (i) displaying the plurality of application devices managed in a security policy management system in a single pane view; (ii) adding new application devices to a device inventory; (iii) automatically generating a trend line graph to display a configuration changes of the plurality of application specific objects over a period of time; (iv) defining a logic for searching and fetching a plurality of rules and a plurality of policies across the plurality of application devices; (v) defining a new security policy to the plurality of application specific objects; and (vi) implementing the new security policy to modify a plurality of user details and a rule and a policy information associated with the plurality of application specific objects.