Firewall Ticket Identifier for Automated Access Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face inefficiencies in accessing network destinations due to unknown security device configurations and the time-consuming process of identifying and reconfiguring multiple security devices to allow packet forwarding, especially when the path through the network is dynamic and involves numerous security devices.
Innovation Solution
A system and method that utilize a ticket identifier within packets to facilitate path testing and access management, where security devices log packet dispositions and automatically reconfigure to permit access, leveraging a self-help portal, access authority, and log server to streamline the process of identifying and modifying security device configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security devices block packets to prevent unauthorized access, then network security is improved, but user access to legitimate destinations becomes difficult and time-consuming
Solution Approach 1:
The system enables security devices to automatically identify and permit legitimate traffic through self-service mechanisms. When a user sends packets with valid ticket identifiers, security devices autonomously log the dispositions and reconfigure their access control lists to permit the traffic, eliminating the need for manual administrator intervention and significantly improving user access ease while maintaining security through automated validation
2Reliability
If multiple security devices are configured to block packets, then security coverage is improved, but the complexity of identifying and reconfiguring devices increases
Solution Approach 1:
The system implements feedback mechanisms where security devices automatically log packet dispositions (blocked or permitted) and this information is fed back to the user through a portal. Users can query which security devices blocked their packets and receive automated reconfiguration requests, significantly reducing the complexity of managing multiple security devices while maintaining comprehensive security coverage
Solution Approach 2:
A portal server acts as an intermediary between users and multiple security devices. The portal receives user access requests, coordinates with security devices to identify blocking devices, and manages the reconfiguration process. This intermediary layer abstracts the complexity of multiple security device configurations from both users and administrators
3Reliability
If security devices silently block packets without notification, then security operation is improved, but user troubleshooting capability deteriorates
Solution Approach 1:
The system transforms silent blocking into informative feedback by having security devices log packet dispositions and communicate this information back to users through a portal. Users receive specific information about which security devices blocked their packets and why, enabling effective troubleshooting while maintaining secure automated blocking operations
Solution Approach 2:
The system changes the 'color' or visibility of blocked packets by attaching ticket identifiers and disposition logs to the packet flow information. This makes previously invisible blocked packets detectable and measurable through the portal interface, allowing users to identify and address blocking issues without compromising security operations
Data Source
AI summary
In a network in which connections are made, between devices or between network segments, through security devices such as firewalls, a user attempting to contact a destination device may be prevented from doing so by some or all of the security devices, which may silently block packets, sent by the user, addressed to the destination device. The remedying of this inability to contact the destination device may be made more difficult by a lack of knowledge, on the part of the user, regarding which security devices are configured to block the packets. As such, a system and method for managing network access are provided.


