Firewall Rule Reordering for Hierarchical Entities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewall rule management in enterprise networks is challenging due to frequent changes in virtualized environments, requiring continuous refinement of rules to maintain secure access without breaking existing policies, and existing solutions lack efficiency in processing large numbers of rules.

Innovation Solution

A system and method that modify the processing order of firewall rules based on hit counts and direct descendent relationships of destination entities, allowing for efficient execution without altering initial policies, using a distributed computer system with a processor and memory to manage firewall rules for hierarchical entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If firewall rules are frequently updated to adapt to virtualized network changes, then network security policy compliance is improved, but rule management complexity and processing time increase

Engineering Contradiction:
Improvenetwork security policy complianceVSAvoidrule management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically reorders firewall rules based on hit counts and hierarchical relationships between destination entities. Rules are periodically repositioned to optimize processing efficiency while maintaining policy compliance, allowing the firewall to adapt to changing network conditions without requiring manual rule creation or complex management interventions

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms by monitoring hit counts of firewall rules and using this information to automatically adjust rule processing order. This closed-loop approach allows the system to learn from actual traffic patterns and optimize its own performance, reducing the need for manual rule management while maintaining security policies

Inventive Principle:
Principle #23Feedback

2Reliability

If all firewall rules are processed sequentially to ensure complete policy enforcement, then security coverage is improved, but CPU resource consumption and processing time increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidCPU resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies different processing priorities to different firewall rules based on their characteristics. Rules with higher hit counts and rules involving hierarchical destination entity relationships are prioritized for faster processing, while less critical rules are processed with lower priority. This differentiated approach maintains comprehensive security coverage while optimizing CPU resource utilization

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The firewall rule processing order is dynamically adjusted based on real-time hit counts and hierarchical relationships. This allows the system to optimize the sequence in which rules are processed, ensuring that critical security policies are enforced efficiently while reducing overall CPU consumption by avoiding sequential processing of all rules when not necessary

Inventive Principle:
Principle #15Dynamics

3Productivity

If firewall rules are reordered based on hit counts to improve processing efficiency, then throughput is improved, but initial firewall policy order may be altered

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidfirewall policy order stability
Core Design Contradiction:
ProductivityVSStability of the object's composition

Solution Approach 1:

The system segments the firewall rule processing into distinct phases: first establishing the initial policy order, then creating optimized reorderings based on hit counts and hierarchical relationships. By separating these concerns and applying reordering only to specific rule subsets while maintaining policy integrity, the system achieves improved processing efficiency without compromising the stability and enforceability of initial firewall policies

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10587578B2Firewall rule management for hierarchical entities
Publication Date: 2020.03.10 VMWARE INC
  • US10587578B2 patent drawing
  • US10587578B2 patent drawing
  • US10587578B2 patent drawing

AI summary

System and method for managing firewall rules for hierarchical entities modify a processing order of the firewall rules to be executed in a distributed computer system based on hit counts of the firewall rules and direct descendent relationships of destination entities of the firewall rules.