Firewall Rule Segmentation in Virtualized Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional firewall configurations in virtualized environments often apply the same set of rules to all compartments, leading to difficulties in managing different trust levels and network interfaces, resulting in potential security breaches and administrative complexities when interfaces move between compartments.

Innovation Solution

The implementation of virtualized environment identifiers and server silo IDs allows for the specification of unique firewall rules for each virtualized environment and server silo, ensuring that filters are applied only to the intended network traffic and interfaces, even if interfaces are added or moved, thereby isolating sessions and users effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the same set of firewall rules is applied to all compartments in a virtualized environment, then device complexity is reduced and ease of operation is improved, but security is compromised and the ability to manage different trust levels is lost

Engineering Contradiction:
Improvefirewall rule managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments firewall rules by associating them with specific virtualized environment identifiers (compartment IDs, silo IDs). This allows different sets of rules to be applied to different compartments while maintaining a unified management interface. The segmentation enables both ease of operation through centralized management and security through compartment-specific rule enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing each virtualized environment (compartment or silo) to have its own customized firewall rules based on its unique identifier. This enables security policies to be tailored to the specific trust levels and requirements of each compartment, while the system maintains overall coherence through the shared filter engine.

Inventive Principle:
Principle #3Local quality

2Reliability

If separate firewall rule sets are implemented for each virtualized environment, then security is improved and different trust levels can be managed, but device complexity and administrative burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidfirewall configuration management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal filter engine that handles multiple virtualized environments through a single shared instance. This multi-functional approach allows the system to enforce compartment-specific rules while using a common infrastructure, thereby improving security without proportionally increasing device complexity. The shared network stack and filter engine serve all compartments efficiently.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces virtualized environment identifiers (compartment IDs, silo IDs) as intermediaries between the firewall rule set and the actual compartments. These identifiers enable the system to apply the correct rules to each compartment without requiring complex direct mapping, simplifying the administrative burden while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If firewall rules are applied based on compartment ID or silo ID, then precise control over network traffic is achieved, but the complexity of rule application and interface management increases

Engineering Contradiction:
Improvetraffic control precisionVSAvoidrule application mechanism
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent implements self-service through automatic rule application. When interfaces are added to or moved between compartments, the system automatically applies the appropriate firewall rules based on the compartment's unique identifier without requiring manual reconfiguration. This maintains precise traffic control while reducing the complexity of rule management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses preliminary action by pre-associating firewall rules with virtualized environment identifiers before interfaces are added to compartments. When interfaces are later added or moved, the correct rules are automatically applied based on these pre-established associations, achieving precise control without increasing operational complexity.

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If a single shared filter engine and network stack are used across all virtualized environments, then device complexity is reduced and resource utilization is improved, but the ability to isolate sessions and users is compromised

Engineering Contradiction:
Improvesystem architectureVSAvoidsession isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the network processing space by introducing virtualized environment identifiers that logically divide the shared filter engine and network stack into isolated processing paths for each compartment. This segmentation enables session isolation while maintaining the efficiency benefits of a shared infrastructure, as each compartment's traffic is processed with its own set of rules applied by the shared engine.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8151337B2Applying firewalls to virtualized environments
Publication Date: 2012.04.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8151337B2 patent drawing
  • US8151337B2 patent drawing
  • US8151337B2 patent drawing

AI summary

Each virtualized environment on a computer has its own set of firewall rules. The virtualized environments share a single instance of the operating system image, a filter engine and a single network stack. A virtualized environment may be a compartment or a server silo. A virtualized environment is a network isolation mechanism and may be used to prevent use of a computer to traverse network boundaries by creating a separate virtualized environment for each network, enabling a separate set of rules to be applied to each virtualized environment and the network interfaces within it. Virtualized environments may also be used to assign different trust levels to the same physical network. Firewall rules are applied by virtualized environment identifier (ID), enabling separate filters to be applied to each virtualized environment on a computer. A virtualized environment may include or be associated with one or more network interfaces.