Firewall Configuration Automation via Source Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data center management systems lack efficient mechanisms for configuring network-based firewall services to effectively process and prioritize network address ranges, leading to potential security vulnerabilities and resource inefficiencies.

Innovation Solution

A system that processes and prioritizes network firewall configuration information, allowing for the filtering and formatting of network address ranges to configure network firewalls within data centers, enabling the blocking, filtering, or further processing of communications based on specified address ranges, while also considering weights and historical performance adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network firewall configuration is manually managed without automated prioritization, then configuration accuracy may be maintained, but security vulnerabilities increase and resource efficiency decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables automated self-service configuration of firewall rules by collecting network address ranges from multiple sources, assigning weights based on trust levels, automatically prioritizing ranges, and generating configuration files without manual intervention. This resolves the contradiction by making the system self-configuring while maintaining both security and efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring network traffic patterns, evaluating the effectiveness of firewall rules, and adjusting priorities based on historical performance data. This closed-loop approach ensures security improvements while optimizing resource utilization through data-driven decisions.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If multiple sources provide network firewall configuration information, then comprehensiveness of security coverage improves, but complexity of processing and prioritization increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system transforms the complex multi-source configuration problem into a manageable parameter-based system by assigning numerical weight values to different sources based on their trust levels. This parameterization allows automated sorting and prioritization, reducing processing complexity while maintaining comprehensive security coverage from multiple sources.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If network address ranges are extensively filtered and formatted, then firewall configuration precision improves, but processing time increases

Engineering Contradiction:
Improveconfiguration precisionVSAvoidprocessing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs preliminary filtering, formatting, and validation of network address ranges during the configuration collection phase, before the actual firewall rule generation. By preparing the data in advance with proper formatting and duplicate removal, the system reduces the processing time required during rule generation while maintaining high configuration precision.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10116698B1Managing network firewall configuration utilizing source lists
Publication Date: 2018.10.30 AMAZON TECH INC
  • US10116698B1 patent drawing
  • US10116698B1 patent drawing
  • US10116698B1 patent drawing

AI summary

Systems and methods for configuration of network-based firewall services based on network firewall configuration information provided by one or more sources are provided. The network firewall configuration information can include one or more lists of network address ranges that will be used by the network firewall to process data communications received at a data center. The received network firewall configuration information can be prioritized and filtered to conform to a maximum threshold number of network address ranges that can be configured on a network firewall service. The filtered and processed network address range information can then be utilized to configure one or more network firewall services or application hosted within a data center.