Firewall Rule Group Reuse for Network Policy Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual updating of security policies in large networks with many endpoints is time-consuming and inefficient, as existing policies need to be respected while accommodating new flows, leading to a need for automated techniques to optimize firewall rules.

Innovation Solution

A network analysis appliance identifies and optimizes existing firewall rules by categorizing flows into intra-application, ingress, and egress flows, finding closest matching rules, and modifying source and destination addresses to include new addresses, while using user-specified thresholds to balance existing group reuse and new group creation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual updating of security policies is performed to respect existing policies while accommodating new flows, then policy accuracy and compliance are improved, but time consumption and operational efficiency deteriorate

Engineering Contradiction:
Improvepolicy accuracyVSAvoidtime consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system automatically analyzes observed network flows and generates updated firewall rules without requiring manual administrator intervention. The appliance self-services the policy update process by comparing observed flows against existing rules, identifying leaks, and producing modified rules that maintain compliance with existing policies while accommodating new legitimate traffic patterns.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of policy updating is replaced with an automated computational system. The network analysis appliance uses algorithmic processing to analyze flows, match patterns, and generate rules, substituting human manual work with automated electronic processing that is both faster and more consistent.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If automated techniques are used to update firewall rules, then productivity and efficiency are improved, but device complexity and system sophistication worsen

Engineering Contradiction:
Improveupdate efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The network analysis appliance serves as an intermediary between the existing firewall system and the observed network flows. It processes flow data, applies analysis algorithms, and generates rule recommendations without directly modifying the core firewall infrastructure, thereby automating the update process while maintaining system stability and managing complexity through a dedicated intermediate component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The automated update process is segmented into distinct functional modules: flow observation, rule matching, leak identification, and rule generation. This segmentation allows each component to be independently developed and maintained, managing overall system complexity through modular architecture while achieving high productivity through coordinated automated operations.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If existing firewall rules are modified to accommodate new flows, then adaptability and policy completeness are improved, but risk of policy errors and security vulnerabilities worsen

Engineering Contradiction:
Improvepolicy completenessVSAvoidpolicy error risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system continuously observes network flows and uses this feedback to identify leaks (unauthorized or unintended traffic patterns). By comparing observed flows against existing firewall rules, the system detects gaps in policy coverage and generates corrective rules, creating a closed-loop feedback mechanism that improves policy completeness while maintaining reliability through systematic analysis rather than ad-hoc modifications.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis of observed flows before generating rule modifications. By pre-processing flow data, identifying patterns, and validating proposed changes against existing policies, the system prepares comprehensive update recommendations that reduce the risk of errors when rules are actually applied, ensuring adaptability improvements are made safely and systematically.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12015591B2Reuse of groups in security policy
Publication Date: 2024.06.18 VMWARE INC
  • US12015591B2 patent drawing
  • US12015591B2 patent drawing
  • US12015591B2 patent drawing

AI summary

Some embodiments provide a method for modifying a firewall rule of a security policy implemented in a network. The method identifies a set of compute machines to be added to a match condition for the firewall rule. The match condition is expressed using one or more groups of compute machines. The method selects a set of groups for the identified set of compute machines from a plurality of existing groups of compute machines based on a user-specified threshold indicating tolerance for inclusion of compute machines that are not in the identified set of compute machines in the selected groups. The method uses the selected set of groups for the match condition of the firewall rule.