Automated Firewall Policy Application for Data Center Micro-Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures in data centers often balance between convenience and security, with perimeter-only firewalls being inadequate against modern threats, and manual intervention being time-consuming and error-prone for comprehensive security solutions.

Innovation Solution

Automatically organizing systems within data centers into application model groups based on security contexts and applying appropriate firewall policies to provide micro-segmentation without manual intervention, using identification, organization, and security modules to select and enforce firewall configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If perimeter-only firewalls are used, then convenience is improved, but security is worsened

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the data center network into multiple security zones or segments, each with its own firewall policies. Instead of a single perimeter firewall, the system creates micro-segments throughout the network, allowing security policies to be applied at granular levels. This segmentation enables both convenience (through automated policy application) and security (through comprehensive coverage).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an automated policy management system that acts as an intermediary between security requirements and firewall configuration. This intermediary automatically translates security policies into firewall rules and applies them consistently across the network, reducing manual effort while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If thorough defensive measures are implemented, then security is improved, but IT resource burden is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidIT resource burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service automated system that independently manages firewall policy deployment. The system automatically discovers network assets, evaluates security requirements, generates appropriate firewall policies, and applies them without requiring extensive manual IT intervention. This self-service capability maintains thorough security while significantly reducing the IT resource burden.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent dynamically adjusts firewall policy parameters based on network conditions, asset types, and security requirements. Rather than maintaining static complex configurations, the system automatically modifies policy parameters to match current needs, reducing the burden of manual management while maintaining comprehensive security coverage.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If manual firewall policy application is used, then security context control is improved, but time consumption is worsened

Engineering Contradiction:
Improvesecurity context controlVSAvoidtime consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining security contexts and policy templates that can be automatically applied to network assets. When new assets are discovered or existing assets change, the system automatically matches them with appropriate pre-defined policies, maintaining precise security context control without time-consuming manual configuration for each asset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the manual mechanical process of firewall policy configuration with an automated computational system. The system uses algorithms to automatically analyze asset attributes, determine appropriate security contexts, and apply corresponding policies, thereby maintaining precision while eliminating time-consuming manual operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3241331B1Systems and methods for automatically applying firewall policies within data center applications
Publication Date: 2020.04.15 CA TECH INC
  • EP3241331B1 patent drawingFigure 1
  • EP3241331B1 patent drawingFigure 2
  • EP3241331B1 patent drawingFigure 3

AI summary

The disclosed method may include (1) identifying a data center application whose functionality is provided by a set of systems, (2) organizing, automatically by the computing device, the set of systems into one or more application model groups by, for each system in the set of systems, identifying an attribute of the system that is indicative of a security context under which the system should operate and assigning the system to an application model group for which the security context will be provided, and (3) for each application model group in the one or more application model groups, protecting the application model group by selecting a firewall configuration that will provide the security context for the application model group and by using the selected firewall configuration to protect the application model group. Various other methods, systems, and computer-readable media are also disclosed.