Firewall Policy Modeling via Binary Decision Diagrams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing complex firewall policies with thousands of rules becomes overwhelming for network managers due to the difficulty in understanding and tracking changes, leading to increased complexity and risk of network security breaches.

Innovation Solution

A method and system that model network device policies using bit strings, create hierarchical decision diagrams, and translate them into numerical intervals, providing a comprehensible policy rule set that simplifies the management of firewall policies by condensing them into human-readable rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall rules are continuously added to address new threats, then network security coverage is improved, but policy complexity increases making management overwhelming

Engineering Contradiction:
Improvenetwork security coverageVSAvoidfirewall policy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex firewall policy into multiple simplified views: (1) policy rules are organized into policy rule sets grouped by function or threat type, (2) hierarchical decision diagrams break down rule evaluation logic into manageable decision nodes, (3) change tracking separates individual rule modifications from the overall policy. This segmentation allows security coverage to expand while management complexity remains controlled through modular organization.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If detailed firewall rules are implemented to cover all threats, then security accuracy is improved, but understanding and tracking changes becomes difficult

Engineering Contradiction:
Improvesecurity rule precisionVSAvoidpolicy change tracking difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary change tracking mechanism that mediates between detailed firewall rules and administrator understanding. The system captures rule modifications, translates them into structured change representations, and presents them through hierarchical decision diagrams that show only relevant changes. This intermediary layer maintains precise security rules while making change tracking manageable through selective visualization.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive policy rules are maintained for all network threats, then security coverage is improved, but ease of management deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidfirewall policy management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic policy representation through hierarchical decision diagrams that adapt to different management needs. The system dynamically generates simplified views of the firewall policy based on current operations, allowing administrators to interact with only the relevant portions of the policy at any given time. This dynamic presentation maintains comprehensive security coverage while improving ease of operation through context-aware simplification.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9578061B2System and method for modeling a networking device policy
Publication Date: 2017.02.21 FIREMON LLC
  • US9578061B2 patent drawing
  • US9578061B2 patent drawing
  • US9578061B2 patent drawing

AI summary

Implementations of the present disclosure involve a system and/or method for modeling a networking device policy or set of rules and/or transforming a networking device policy model into a set of comprehensible rules for presentation to a manager of the device. In one embodiment, the system and/or method includes converting one or more rules of the firewall device into a string of representative bits, creating a binary decision diagram from the converted rules of the firewall policy, transforming the binary decision diagram into a ternary tree diagram and analyzing the ternary tree diagram to condense the firewall policy into one or more rules comprehensible by a user of the firewall.