Automated Firewall Rule Reduction via Routing and Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls in IP networks face performance and security issues due to numerous obsolete and unused rules that cannot be automatically removed, complicating network accessibility and potentially allowing unauthorized access.

Innovation Solution

The method utilizes network routing information and firewall rule configuration data to analyze access logs, identifying and removing obsolete rules without disrupting current operations by periodically identifying unused rules for each external partner network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analytical processes are used to identify and remove obsolete firewall rules, then rule accuracy can be maintained, but the complexity and time required increases significantly

Engineering Contradiction:
Improveaccuracy of obsolete rule identificationVSAvoidcomplexity of manual analytical processes
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that acts as a bridge between firewall rule management and analysis. This intermediary automatically collects routing information, firewall configuration data, and access logs, then processes them to identify obsolete rules. The intermediary eliminates the need for complex manual analysis while maintaining high accuracy through systematic automated comparison of rule usage against current network state.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically identifying obsolete firewall rules without requiring manual intervention. The automated process continuously monitors access logs, compares them against current routing information and active rules, and generates recommendations for removal. This self-service capability maintains precision while dramatically reducing operational complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If numerous firewall rules are maintained in the system, then network security coverage is improved, but system performance deteriorates due to processing overhead

Engineering Contradiction:
Improvenetwork security coverageVSAvoidfirewall processing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts and removes obsolete firewall rules from the active rule set based on automated analysis of access logs and routing information. By identifying and taking out rules that are no longer needed (those that have not been matched in access logs and are not consistent with current routing), the system maintains comprehensive security coverage for active rules while reducing the overall rule count to improve processing performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system discards obsolete firewall rules that consume processing resources without providing security value. By continuously monitoring rule usage and discarding unused rules, the system recovers firewall processing performance while maintaining necessary security coverage. The discarded rules are those that do not match current network traffic patterns or routing configurations.

Inventive Principle:
Principle #34Discarding and recovering

3Adaptability or versatility

If firewall rules are frequently modified to adapt to changing network conditions, then adaptability is improved, but tracking rule usage becomes impossible due to changing rule IDs

Engineering Contradiction:
Improvefirewall rule adaptabilityVSAvoidloss of rule usage history
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent replaces the mechanical system of tracking rule IDs with an automated information technology-based analysis system. Instead of manually tracking rule identifiers through changes, the system automatically collects access logs, parses firewall configuration files to understand current rule states, and analyzes traffic patterns. This substitution enables continuous adaptability while maintaining usage information through automated data collection and analysis rather than manual tracking.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements feedback by continuously monitoring access logs to determine which firewall rules are actually being used. This feedback mechanism allows the system to adapt to changing network conditions by identifying rules that are no longer matched by traffic patterns. The feedback loop maintains information about rule usage despite rule ID changes, as the system analyzes actual traffic matching behavior rather than relying on static rule identifiers.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If obsolete firewall rules are not removed, then network accessibility is maintained for all potential connections, but security vulnerabilities increase due to unauthorized access risks

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the firewall rule set adaptive rather than static. The system continuously analyzes access logs and routing information to dynamically identify which rules are obsolete. By making the rule set dynamic and automatically updating it based on current network conditions, the system maintains accessibility for legitimate connections while removing obsolete rules that could create security vulnerabilities. The dynamic approach ensures that accessibility is maintained for active connections while eliminating security risks from unused rules.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7665128B2Method and apparatus for reducing firewall rules
Publication Date: 2010.02.16 RAKUTEN GROUP INC
  • US7665128B2 patent drawing
  • US7665128B2 patent drawing
  • US7665128B2 patent drawing

AI summary

A method and apparatus for reducing obsolete firewall rules are disclosed. The present invention addresses the issue by using existing network routing information as well as firewall rule configuration information to help analyze firewall access logs to identify obsolete and unused firewall rules so that these obsolete firewall rules can be removed. In one embodiment, the present invention is capable of periodically identifying the unused rule set for each external partner network and removing these obsolete rules with no impact to the current operation.