Firewall Rule Aggregation in Virtualized Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewall rule creation in virtualized computing environments is inefficient, leading to inaccurate micro-segmentation and increased security threats due to the creation of numerous 'pinholes' for ephemeral port numbers during application-layer protocol sessions, which complicates data center security.

Innovation Solution

The process of firewall rule creation is improved by associating control and data flows of application-layer protocol sessions, allowing firewall rules to be created based on control flows and indirectly applying them to data flows, reducing the number of pinholes needed and enhancing security by optimizing firewall rule creation through a tree structure-based approach.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewall rule creation is used to protect each virtual machine, then security coverage is improved, but the number of firewall rules increases excessively

Engineering Contradiction:
Improvesecurity coverageVSAvoidnumber of firewall rules
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual firewall rules for different virtual machines into a single aggregated firewall rule at the host level. Instead of creating separate rules for each VM, the system combines traffic patterns from multiple VMs and generates one consolidated rule that applies to the entire host, thereby reducing rule complexity while maintaining security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates firewall rules with universal applicability that can protect multiple virtual machines simultaneously. By abstracting common traffic patterns and creating host-level rules that apply universally across multiple VMs, the system reduces the total number of rules needed while maintaining comprehensive security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If individual firewall rules are created for each flow, then traffic control precision is improved, but the number of pinholes increases

Engineering Contradiction:
Improvetraffic control precisionVSAvoidnumber of pinholes
Core Design Contradiction:
Manufacturing precisionVSQuantity of substance

Solution Approach 1:

The patent combines multiple individual flow-based firewall rules into aggregated host-level rules. By merging traffic patterns from multiple VMs and flows into consolidated rules, the system maintains precise traffic control for each flow while reducing the total number of pinholes created in the firewall.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent shifts the firewall rule creation from the VM level to the host level, changing the dimensional scope of rule application. This dimensional shift allows individual flow precision to be maintained through proper rule formulation while reducing the overall number of pinholes by applying rules at a higher abstraction level.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If comprehensive firewall rules are created for all protocols, then security coverage is improved, but rule management complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidrule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges comprehensive protocol-specific firewall rules into aggregated host-level rules. By combining rules for different protocols and applications into consolidated rules at the host level, the system maintains comprehensive security coverage while significantly reducing rule management complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal firewall rules that can handle multiple protocols and applications simultaneously. These host-level rules are designed to be multi-functional, covering various protocols and traffic patterns with a single rule formulation, thereby reducing management complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10320749B2Firewall rule creation in a virtualized computing environment
Publication Date: 2019.06.11 VMWARE INC
  • US10320749B2 patent drawing
  • US10320749B2 patent drawing
  • US10320749B2 patent drawing

AI summary

Example methods are provided for a network management entity to perform firewall rule creation in a virtualized computing environment. The method may comprise obtaining flow data associated with an application-layer protocol session between a first endpoint and a second endpoint in the virtualized computing environment; and identifying, from the flow data, an association between a control flow and at least one data flow of the application-layer protocol session. The method may also comprise: based on the association, creating a firewall rule that is applicable to both the control flow and at least one data flow; and instructing a first firewall engine associated with the first endpoint, or a second firewall engine associated with the second endpoint, or both, to apply the firewall rule during the application-layer protocol session.