Selective Firewall Exception Revocation by Network Class

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls often face security risks due to unmanaged exceptions across different networks, leading to increased security risks when high-security settings are applied to less secure networks, and decreased usability from repeated exception enabling/disabling.

Innovation Solution

Implementing a system where firewall security settings, such as exceptions, can be selectively applied and automatically revoked based on triggering events and network classification, using persistence flags to maintain or revoke exceptions across specified network classes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall exceptions are enabled for a high-security network, then security is improved, but security risk increases when the same exception is applied to a less secure network

Engineering Contradiction:
Improvefirewall securityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different firewall exception settings to different network classes. High-security networks receive enabled exceptions while less secure networks receive disabled exceptions, making the security configuration locally adapted to each network's security requirements rather than uniformly applied across all networks.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the state parameter of firewall exceptions based on network class. The exception enable/disable state is dynamically adjusted according to the security level of the network being accessed, transforming a static firewall configuration into a dynamic one that adapts to different operational contexts.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If firewall exceptions are manually enabled for each network, then security control is improved, but usability deteriorates due to repeated user intervention

Engineering Contradiction:
Improvesecurity controlVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The firewall system automatically manages exception states based on detected network class without requiring user intervention. The system serves itself by monitoring network connections, classifying them according to security levels, and automatically enabling or disabling appropriate exceptions, eliminating the need for manual user configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback loop where network connection information is continuously monitored and fed back to the firewall exception management logic. Based on this feedback about which network is currently active, the system automatically adjusts exception states, creating a closed-loop control system that adapts to changing network conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8214889B2Selective auto-revocation of firewall security settings
Publication Date: 2012.07.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8214889B2 patent drawing
  • US8214889B2 patent drawing
  • US8214889B2 patent drawing

AI summary

Management of security firewall settings in a networked computing environment is described. One example embodiment includes applying security settings and exceptions to the security settings based on network class for network communication, and upon detection of an event, revoking at least one exception for at least one network in a specified class.