Firewall Policy Management via Host Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing millions of network firewall policies or rules across tens or hundreds of thousands of computer hosts in an enterprise is inefficient and scalable challenges exist in existing systems.
Innovation Solution
A system and method that updates network policies by determining a subset of hosts to update, identifying relevant policies for each host, and installing these policies, using a category like time zone to divide hosts and leveraging a shared file system for policy distribution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network policies are updated for all hosts simultaneously, then policy coverage is complete, but system complexity and update time increase significantly
Solution Approach 1:
The patent segments hosts into subsets based on categories such as time zone, geographic location, or organizational unit. Instead of updating all hosts simultaneously, the system updates one subset at a time, reducing the complexity of concurrent updates while maintaining comprehensive policy coverage across all hosts over time.
Solution Approach 2:
The system dynamically determines which hosts belong to which subsets based on configurable criteria. The categorization can be adjusted flexibly to change over time, allowing the system to adapt to evolving organizational needs while managing update complexity through dynamic subset management.
2Reliability
If network policies are updated for all hosts simultaneously, then policy coverage is complete, but update time increases significantly
Solution Approach 1:
By dividing hosts into time-based or geographic subsets, the system can perform updates in parallel across different groups without interfering with each other. This segmentation reduces the total update time while ensuring all hosts receive the policies, as each subset can be updated independently during different time windows.
Solution Approach 2:
The system implements periodic updates where different subsets of hosts are updated at different time periods. This allows the system to maintain continuous policy coverage while spreading the update workload over time, reducing the peak update time and avoiding simultaneous updates across all hosts.
3Manufacturing precision
If individual firewall rules are managed on each host, then policy precision is high, but management efficiency decreases
Solution Approach 1:
Instead of managing individual firewall rules on each host, the system creates a centralized policy definition that is copied and applied to multiple hosts simultaneously. This copying approach maintains policy precision through consistent rule definitions while dramatically improving management efficiency by eliminating the need to manually configure each host individually.
Solution Approach 2:
The system implements a universal policy management mechanism that can apply the same policy definition across multiple host types and configurations. This multi-functional approach allows a single policy to serve multiple purposes and hosts, improving management efficiency while maintaining precision through structured policy templates.
4Productivity
If centralized policy management is implemented, then management efficiency improves, but system complexity increases
Solution Approach 1:
The system introduces a policy management intermediary layer that sits between the centralized policy definitions and the individual hosts. This intermediary handles the complexity of policy distribution, subset management, and timing, allowing centralized management to improve efficiency without directly increasing the complexity visible at the host level or in the management interface.
Data Source
AI summary
A system and method may update network policies by determining, among a set of hosts, a subset of hosts to have network policies updated; for each host in the subset of hosts, determining a set of policies relevant to the host; and for each of the subset of hosts, installing the set of policies relevant to the host. The subset of hosts may be determined based on a category or division such as the time zone corresponding to the location of each host in the subset of hosts. The policies relevant to the host may be received from a database and saved to a file with the set of policies relevant to the host; the host may then access the file.


