Network Firewall Policy Clustering and Ranking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in efficiently managing firewall policies, leading to high latency and potential unauthorized data packets due to manual errors and unplanned policy management, which can result in security vulnerabilities.

Innovation Solution

A method and system that monitor real-time parameters such as inbound and outbound transmission times, jitter hit rate, hit count, and last hit time for each policy, estimating a hit count percentage to group policies into clusters, thereby automating the management and scanning of data packets based on policy rankings, reducing manual intervention and errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If policies are manually assigned and inserted in existing systems, then administrators can control network traffic, but manual errors occur leading to high latency and unauthorized data packets slipping through

Engineering Contradiction:
Improvepolicy management accuracyVSAvoidmanual workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically monitors, analyzes, and optimizes firewall policies without requiring continuous manual intervention. The policy management system self-adjusts by grouping similar policies, reordering them for optimal performance, and removing redundant rules based on automated analysis of network traffic patterns and security requirements

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous monitoring of network traffic and policy effectiveness, using this feedback to automatically refine and optimize firewall rules. The automated system learns from traffic patterns and adjusts policy ordering and grouping to improve both security and performance over time

Inventive Principle:
Principle #23Feedback

2Reliability

If firewalls control incoming and outgoing network traffic using manual policies, then network security is maintained, but data packets undergo high latency in security checks due to manual errors in policy insertion

Engineering Contradiction:
Improvenetwork securityVSAvoidlatency in security checks
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis and optimization of firewall policies before they are applied to network traffic. By pre-grouping similar policies, pre-ordering them for optimal evaluation sequence, and pre-removing redundant rules, the system minimizes the time required for actual security checks during normal operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments firewall policies into logical groups based on similarity and security requirements. This segmentation allows the system to evaluate policies in an optimized sequence, processing related policies together and skipping redundant evaluations, thereby reducing overall latency in security checks

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If administrators manually manage firewall policies, then policies can be assigned, but unplanned management occurs causing malicious data packets to slip into the network stream

Engineering Contradiction:
Improvepolicy assignment capabilityVSAvoidsecurity against malicious packets
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system continuously monitors network traffic patterns and automatically adjusts firewall policies to address emerging threats. By self-managing policy updates and optimizations, the system reduces reliance on human administrators who may make errors or fail to respond promptly to new attack vectors

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous monitoring of network traffic and policy effectiveness, using this feedback to automatically refine and optimize firewall rules. The automated system learns from traffic patterns and adjusts policies in real-time to maintain security against evolving threats

Inventive Principle:
Principle #23Feedback

4Reliability

If firewalls use manual policy management, then basic security control is achieved, but the system cannot reduce manual workloads such as assigning new policies and grouping similar policies

Engineering Contradiction:
Improvebasic security controlVSAvoidmanual workload reduction
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system automatically performs policy management tasks including assigning new policies, grouping similar policies, removing redundant rules, and optimizing policy order. This self-service capability eliminates the need for administrators to manually perform these repetitive tasks while maintaining and enhancing security control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The automated policy management system performs multiple functions simultaneously: it monitors network traffic, analyzes policy effectiveness, groups similar policies, reorders policies for optimal performance, removes redundant rules, and updates firewall configurations. This multi-functional approach replaces multiple manual processes with a single automated system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3547188B1Method and system for managing policies in a network security system
Publication Date: 2021.08.04 WIPRO LTD
  • EP3547188B1 patent drawingFigure 1
  • EP3547188B1 patent drawingFigure 2
  • EP3547188B1 patent drawingFigure 3a

AI summary

The present disclosure discloses method and policy management system for managing policies in network security system. The policy management system receives one or more data packets from a request source of plurality of request sources, monitors at least one of, an inbound transmission time, an outbound transmission time and a jitter hit rate associated with the one or more data packets and a hit count, a current hit count, last hit time and hit per policy associated with each of plurality of policies of network firewall in real-time. Based on monitoring, policy management system estimates a hit count percentage for each of the plurality of policies and groups plurality of policies into plurality of policy clusters based on hit count percentage associated with each of the plurality of policies. Thus, the present disclosure provides an efficient way of managing network firewall policies without any human intervention.