Firewall Policy Validation via Simulated Packet Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods lack efficiency in testing and validating firewall policies, leading to unintended consequences and user disruption when deploying new or modified policies, as administrators often roll back changes due to the complexity of policies and lack of effective testing tools.

Innovation Solution

A method and device for testing firewall policies by obtaining packet parameters, applying policies to generate policy logs and hit counts, allowing administrators to visualize and validate policies in a simulated or live environment before deployment, thereby reducing the need for policy rollbacks and minimizing user disruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If firewall policies are deployed without thorough testing, then deployment speed is improved, but policy reliability deteriorates due to unintended consequences

Engineering Contradiction:
Improvedeployment speedVSAvoidpolicy reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary testing of firewall policies in a simulated environment before actual deployment. Packet capture data is used to pre-validate policy rules, allowing administrators to identify and fix issues beforehand, thus maintaining both fast deployment and high reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a simulated environment that copies the actual network topology and traffic patterns. This virtual replica allows policy testing without affecting live systems, enabling reliable validation while maintaining deployment speed through parallel processing.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive firewall policies with many rules are implemented, then security coverage is improved, but device complexity increases making testing difficult

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex firewall policy into individual rules and groups them by function. Each rule can be tested independently using packet capture data, making the overall complex policy manageable and easier to validate while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces a simulated environment as an intermediary between policy authors and the actual firewall deployment. This mediator layer handles the complexity by providing a controlled testing ground where policies can be validated against real traffic patterns without affecting production systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If policy testing is performed in live environment, then validation accuracy is improved, but user disruption increases

Engineering Contradiction:
Improvevalidation accuracyVSAvoiduser disruption
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system creates a copy of the live network environment in a simulated topology that replicates traffic patterns and device configurations. This allows accurate validation of firewall policies using real packet capture data without disrupting actual users, as testing occurs in the virtual replica rather than production systems.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs all validation testing in advance in the simulated environment before any changes are applied to live systems. This preliminary action ensures accuracy is achieved without user disruption, as all testing completes beforehand and only successful policies are deployed.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If rollbacks are performed when issues arise, then policy reliability is maintained, but loss of time increases

Engineering Contradiction:
Improvepolicy reliabilityVSAvoidrollback time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs comprehensive testing in the simulated environment before deployment, so that issues are identified and resolved in advance. This eliminates the need for rollbacks after deployment, as policies are validated to work correctly in the live environment before being applied, thus maintaining reliability while eliminating time loss from rollbacks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9553845B1Methods for validating and testing firewalls and devices thereof
Publication Date: 2017.01.24 F5 NETWORKS INC
  • US9553845B1 patent drawing
  • US9553845B1 patent drawing
  • US9553845B1 patent drawing

AI summary

A method, non-transitory computer readable medium, and traffic management computing device that obtains one or more parameters for a packet. Firewall policies each corresponding to a logical firewall are applied to the parameters for the packet. A policy log for each of at least a subset of the firewall policies or a hit count for one or more of rules in an access list of each of the subset of the firewall policies is generated. The policy log includes an indication of one or more actions corresponding to at least one rule in the access list of each of the subset of the firewall policies, wherein the at least one rule matches one or more of the parameters of the packet. At least one of the generated policy log or hit counts for one or more of the at least a subset of the firewall policies is output.