Firewall Policy Modeling via Spanning Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing complex firewall policies in dynamic networks is challenging due to the overwhelming number of rules and increasing complexity, making it difficult for network managers to accurately understand and maintain firewall behavior, especially with multiple ingress and egress interfaces, traffic routing tables, and network address translation.

Innovation Solution

A method and system for modeling firewall behavior by converting rules into a spanning graph that represents ingress and egress ports, behavior groups, and communication pathways, allowing for the creation of a Firewall Policy Diagram that simplifies the understanding and replication of firewall policies across different vendors and networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall rules are increased to defend against new attacks, then security capability is improved, but policy management complexity increases

Engineering Contradiction:
Improvesecurity capabilityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a simplified copy or model of the complex firewall policy through graphical representations. The spanning graph and policy diagrams serve as abstracted copies that capture essential firewall behavior without replicating the full complexity of thousands of individual rules, enabling managers to understand and manage security policies at a higher level of abstraction.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments the complex firewall policy into distinct graphical components including ingress ports, egress ports, behavior groups, and communication pathways. This segmentation allows the policy to be divided into manageable visual elements that can be individually analyzed and understood, reducing the cognitive load on network managers.

Inventive Principle:
Principle #1Segmentation

2Reliability

If firewall rules are increased to defend against new attacks, then security capability is improved, but understanding and maintaining firewall behavior becomes difficult

Engineering Contradiction:
Improvesecurity capabilityVSAvoidunderstanding and maintenance ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a simplified copy or model of the complex firewall policy through graphical representations. The spanning graph and policy diagrams serve as abstracted copies that capture essential firewall behavior without replicating the full complexity of thousands of individual rules, enabling managers to understand and manage security policies at a higher level of abstraction.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces graphical diagrams as an intermediary layer between the complex firewall rule set and the network manager. These diagrams act as a mediator that translates complex rule-based logic into visual representations, making it easier for humans to understand, analyze, and maintain firewall behavior without directly interacting with the underlying complex rule sets.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple ingress and egress interfaces, routing tables, and NAT are added to broaden firewall functionality, then adaptability is improved, but modeling complexity increases

Engineering Contradiction:
Improvefirewall functionalityVSAvoidmodeling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complex firewall policy into distinct graphical components including ingress ports, egress ports, behavior groups, and communication pathways. This segmentation allows the policy to be divided into manageable visual elements that can be individually analyzed and understood, reducing the cognitive load on network managers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal graphical modeling framework that can represent multiple firewall functionalities (ingress/egress interfaces, routing tables, NAT) using a common set of visual elements and relationships. This universal approach allows diverse firewall features to be modeled consistently within a single diagramming system, reducing the need for separate modeling approaches for each feature type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9270704B2Modeling network devices for behavior analysis
Publication Date: 2016.02.23 FIREMON LLC
  • US9270704B2 patent drawing
  • US9270704B2 patent drawing
  • US9270704B2 patent drawing

AI summary

Implementations of the present disclosure involve a system and/or method for modeling a firewall function and operation such that software based analysis and other formal analysis methods may be used with the model. In one embodiment, the system and/or method includes modeling the function of a firewall as a set of links, ingress/egress interfaces, interface switches and behaviors chained together into a spanning graph. The spanning graph may then be used in conjunction with data structures, such as a Firewall Policy Diagram, to illustrate pathways through a network for a communication packet. This system and/or method allows for the understanding of a firewall policy such that the policy can be replicated among various firewalls in the network at issue.