Firewall Configuration Automation via Risk-Based Expert System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewall administrators face significant time and resource challenges in assessing and making decisions on firewall configuration changes due to the manual and inconsistent analysis of data, leading to delays and potential misidentification of valid traffic.

Innovation Solution

An expert system is implemented to analyze message flow data, assign risk values, and generate proposals for altering firewall configurations based on predefined security guidelines, automating the assessment process and reducing manual effort.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual assessment of firewall configuration changes is performed by administrators, then security policy compliance can be evaluated, but significant time and human resources are consumed leading to delays

Engineering Contradiction:
Improvesecurity policy compliance evaluationVSAvoidtime for configuration change assessment
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the firewall configuration assessment is performed automatically by the system itself rather than requiring manual administrator intervention. The automated system collects data, evaluates security policies, and generates recommendations without human involvement in the assessment process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of administrator assessment is replaced with an automated computational system that uses data collection, risk value assignment, and algorithmic evaluation to perform security policy compliance assessment, eliminating the need for human manual analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual analysis of firewall data is performed, then security assessments can be conducted, but inconsistent analysis results occur across different assessments

Engineering Contradiction:
Improvesecurity assessment consistencyVSAvoidmanual analysis process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system transforms qualitative manual analysis into quantitative automated evaluation by assigning numerical risk values to different data elements. This parameterization ensures consistent, reproducible results across different assessments through standardized calculation methods.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The inconsistent manual analysis process is replaced with a standardized automated computational system that applies consistent rules and algorithms to all assessments, eliminating variability introduced by different administrators or assessment approaches.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive data collection for firewall assessment is performed, then accurate security evaluation can be achieved, but the complexity of the assessment process increases

Engineering Contradiction:
Improvesecurity evaluation accuracyVSAvoidassessment process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The comprehensive assessment process is segmented into distinct modular components: data collection module, risk value assignment module, total risk calculation module, and recommendation generation module. Each module handles a specific aspect of the assessment, making the overall complex process manageable and systematic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal automated assessment platform that handles multiple aspects of firewall evaluation through a single integrated system. This multi-functional system performs data collection, analysis, risk calculation, and recommendation generation, reducing operational complexity despite comprehensive evaluation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7937353B2Method and system for determining whether to alter a firewall configuration
Publication Date: 2011.05.03 WRP IP MANAGEMENT LLC
  • US7937353B2 patent drawing
  • US7937353B2 patent drawing
  • US7937353B2 patent drawing

AI summary

A method and system for determining whether to alter a firewall configuration. Message flow data associated with a message packet blocked by a firewall is received. The packet was blocked based on the firewall not having a message flow rule that permitted passage of the message packet. Risk values associated with a source network, destination network and destination port are identified by the message flow data. Based on the risk values, an electronic recommendation indicating whether to add to the firewall a message flow rule that permits the message flow to pass is determined and generated.