Firewall Rule Merge Module Minimizing Security Vulnerable Space

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls, especially cloud firewalls, face limitations in the number of rules they can register due to memory constraints, leading to security vulnerabilities when trying to manage and merge rules to exceed the maximum registration capacity.

Innovation Solution

An apparatus and method for managing a firewall security policy that includes a rule request module, a rule merge module, and a firewall interface module, which merge pre-applied and requested rules to minimize security vulnerabilities by calculating and selecting rule pairs with the lowest security vulnerable space function values, allowing for efficient registration within limited resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the number of firewall rules is increased to enhance security coverage, then security protection is improved, but the firewall reaches its maximum rule registration capacity due to memory limitations

Engineering Contradiction:
Improvesecurity protectionVSAvoidnumber of rules
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies rule merging by combining multiple firewall rules into consolidated rules. The rule merge module merges pre-applied rules with requested rules, and the system calculates security vulnerable space function values to determine optimal merge candidates. This reduces the total number of rules while maintaining security coverage, allowing the firewall to operate within its memory constraints.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the parameter of rule representation by transforming multiple specific rules into fewer consolidated rules with broader match criteria. By adjusting rule parameters (such as IP address ranges, port ranges, and protocol specifications), the system achieves equivalent or superior security coverage with reduced rule count, enabling the firewall to accommodate more security policies within its resource limits.

Inventive Principle:
Principle #35Parameter changes

2Quantity of substance

If firewall rules are merged to reduce the number of registrations, then the firewall can operate within memory limits, but security vulnerable spaces may occur during the merging process

Engineering Contradiction:
Improvenumber of rulesVSAvoidsecurity vulnerable space
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent implements feedback through the calculation of security vulnerable space function values for each candidate rule pair. The rule merge module evaluates the potential security impact of each merge operation and uses this feedback to guide the merging process. By selecting rule pairs with the lowest security vulnerable space function values, the system minimizes security risks while achieving effective rule consolidation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent converts the potential harm of rule merging (creating security vulnerable spaces) into a benefit by systematically identifying and minimizing these spaces. The security vulnerable space function value calculation transforms the abstract security risk into a quantifiable metric, allowing the system to make informed decisions about which merges are safest and which should be avoided, thus turning a potentially harmful process into a controlled and optimized one.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If multiple requested rules are accumulated and merged, then the firewall can maintain comprehensive security policies, but the complexity of rule management increases

Engineering Contradiction:
Improvesecurity policy coverageVSAvoidrule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the rule management process into distinct functional modules: a rule request module for receiving rules, a requested rule storing module for accumulation, a rule merge module for consolidation, and a firewall interface module for registration. This segmentation divides the complex task of managing numerous security rules into manageable operations, making the system more maintainable and easier to control while achieving comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11582194B2Apparatus and method for managing security policy of firewall
Publication Date: 2023.02.14 SAMSUNG SDS CO LTD
  • US11582194B2 patent drawing
  • US11582194B2 patent drawing
  • US11582194B2 patent drawing

AI summary

An apparatus for managing a security policy of a firewall according to an embodiment includes a rule request module that receives one or more requested rules to be applied to a firewall, a rule merge module that merges a pre-applied rule of the firewall and the one or more requested rules when the number of rules applied to the firewall exceeds a maximum number of rule registrations of the firewall due to the requested rule, and a firewall interface module that receives the pre-applied rule from the firewall and provides the pre-applied rule to the rule merge module, and re-registers a merged rule merged through the rule merge module in the firewall, and the rule merge module is configured to merge the pre-applied rule and the one or more requested rules so that a security vulnerable space occurring due to the merging is minimized.