Unified Gateway Configuration Analysis System for Multi-Vendor Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and analyzing gateway configurations and rules across multiple security devices from different vendors and platforms becomes increasingly complex as the number and complexity of gateways increase, making it difficult to understand and report security policies effectively.

Innovation Solution

A system and method that gathers configuration data from multiple gateway devices, parses and stores it in a unified data structure, and uses an indexing scheme to generate optimized data tables, allowing for centralized analysis and reporting of firewall policies across the enterprise network, with features like bulk queries, customized searches, and export options for easy review.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If configuration data is collected from multiple gateway devices from different vendors and platforms, then comprehensive security policy coverage is improved, but system complexity and difficulty of management increase

Engineering Contradiction:
Improvesecurity policy coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal data structure and analysis system that can handle configuration data from multiple gateway devices from different vendors and platforms. The system uses a standardized data structure with fields for vendor information, device identifiers, policy rules, and configuration parameters that can accommodate diverse gateway types, enabling comprehensive security policy coverage across heterogeneous networks without proportionally increasing management complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary analysis system that acts as a mediator between diverse gateway devices and the security management interface. This intermediary layer collects, standardizes, and analyzes configuration data from multiple vendors' gateways, translating proprietary formats into a unified analysis framework, thereby reducing the complexity burden on end users while maintaining comprehensive coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If detailed configuration data from multiple gateways is analyzed and reported, then reporting accuracy and completeness are improved, but data processing time and resource requirements increase

Engineering Contradiction:
Improvereporting accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining a standardized data structure and analysis framework before data collection. The system establishes predetermined fields and relationships for storing gateway configuration data, enabling efficient processing and rapid generation of accurate reports without requiring complex real-time analysis, thus reducing data processing time while maintaining reporting accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the configuration data into distinct, organized fields including vendor information, device identifiers, policy rules, and configuration parameters. This segmentation allows the system to process specific aspects of gateway configurations independently and efficiently, reducing overall data processing time while maintaining comprehensive and accurate reporting through structured data organization

Inventive Principle:
Principle #1Segmentation

3Speed

If gateway configuration data is stored in unified data structures with indexing, then data retrieval speed is improved, but initial data processing and indexing complexity increase

Engineering Contradiction:
Improvedata retrieval speedVSAvoiddata processing complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by implementing indexing and organization of configuration data during the initial data collection and storage phase. The system creates indexed data structures that map gateway configurations to relevant security policies and rules, enabling rapid data retrieval later without requiring complex real-time processing, thus improving retrieval speed while managing initial processing complexity through automated indexing routines

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9363140B2System and method for analyzing and reporting gateway configurations and rules
Publication Date: 2016.06.07 BANK OF AMERICA CORP
  • US9363140B2 patent drawing
  • US9363140B2 patent drawing
  • US9363140B2 patent drawing

AI summary

A method for analyzing and reporting gateway configurations and rules includes receiving configuration data from gateway devices providing access to an enterprise network. The gateway devices may be associated with multiple vendors. At least one computer processor parses the configuration information associated with each of the gateway devices to identify configuration output data for each of the gateway devices. The configuration output data for each of the gateway devices is stored in a single data structure. The configuration output data stored in the single data structure is indexed to generate one or more optimized data tables.