Firewall Rule Prioritization via Relevancy Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls in data center architectures experience bottlenecks due to slower hardware and inefficient rule application, leading to latency and irrelevant rules being applied despite changes in wireless network applications.

Innovation Solution

A system that stores firewall rules with initial relevancy scores, applies rules based on application identification, updates scores, ranks rules, and disables those below a threshold, improving throughput by optimizing rule application and notification to administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a chain of rules and policies is applied to firewall traffic, then security coverage is improved, but processing speed deteriorates due to hardware limitations

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system pre-calculates and stores relevancy scores for firewall rules when applications are installed or updated. This preliminary action allows the firewall to skip unnecessary rules during traffic processing, directly resolving the contradiction by maintaining comprehensive security coverage while improving processing speed through pre-computed relevance data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The firewall rule relevancy scores are dynamically updated based on application usage status. When applications are removed or updated, the system automatically adjusts which rules remain relevant. This dynamic adaptation allows the firewall to maintain security coverage for active applications while excluding rules for removed applications, thereby improving processing speed without compromising security.

Inventive Principle:
Principle #15Dynamics

2Speed

If firewall hardware is upgraded to be faster, then processing speed is improved, but latency increases due to buffering and filtering requirements

Engineering Contradiction:
Improveprocessing speedVSAvoidlatency
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The system extracts and removes irrelevant firewall rules from the processing chain by disabling rules associated with removed or inactive applications. This extraction principle reduces the number of rules that require buffering and filtering, thereby improving processing speed while minimizing the latency introduced by necessary buffering and filtering operations on relevant rules.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If firewall rules are continuously monitored and updated, then rule relevancy is improved, but system complexity increases

Engineering Contradiction:
Improverule relevancyVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The firewall system automatically monitors application installation and removal events and self-updates its rule relevancy scores without requiring manual administrator intervention. The system services itself by automatically detecting application changes and adjusting firewall rule relevance, thereby improving rule adaptability while minimizing the complexity of manual management procedures.

Inventive Principle:
Principle #25Self-service

4Reliability

If all firewall rules are applied to all traffic, then security coverage is maintained, but productivity decreases due to unnecessary rule processing

Engineering Contradiction:
Improvesecurity coverageVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different processing treatments to different firewall rules based on their relevancy scores. Rules associated with active applications receive full processing attention, while rules for removed applications are disabled or bypassed. This local differentiation maintains security coverage for relevant traffic while improving overall throughput by eliminating processing of irrelevant rules.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10771433B2Automatic management of firewall rules and policies in accordance with relevancy to network traffic of a wireless network
Publication Date: 2020.09.08 FORTINET INC
  • US10771433B2 patent drawing
  • US10771433B2 patent drawing
  • US10771433B2 patent drawing

AI summary

Firewall rules and policies are automatically managed in accordance with relevancy to network traffic on a wireless network. A specific firewall rule is applied to the network packet being examined based on the identified application based on a ranking of a relevancy score. Responsive to the specific firewall rule application, the relevancy score associated with the specific firewall rule are increased, and relevancy scores for other firewall rules of the predetermined firewall rule category that are not applied to the network packet decreased. Firewall rules of the category, for order of application, are ranked based on the relevancy scores. Firewall rules having relevancy scores below a predetermined relevancy threshold are disabled and the administrator is notified.