Network-Aware Firewall Dynamic Security Parameter Adjustment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional host firewalls fail to dynamically adjust security settings based on the type of network a computer is connected to, often leaving public network connections vulnerable by not disabling unnecessary firewall exceptions when switching from a private to a public network.

Innovation Solution

A network-aware firewall system that determines the type of network a client computer is connected to and dynamically modifies its security parameters by prompting the user to select the network type, allowing for the enforcement of specific security profiles for private and public networks, thereby enabling or disabling exceptions accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional host firewalls enforce static allow/block rules, then ease of operation is improved, but security is worsened because exceptions remain enabled when connecting to public networks

Engineering Contradiction:
Improvefirewall rule managementVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The firewall system dynamically adjusts security parameters based on network type detection. When the system detects a public network connection, it automatically modifies firewall exceptions to block incoming connections. This dynamic adaptation resolves the contradiction by making firewall rules flexible rather than static, maintaining ease of operation while improving security reliability through context-aware rule enforcement.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes firewall security parameters based on the detected network environment. Specifically, it modifies the state of firewall exceptions (allow/block) according to whether the network is identified as private or public. This parameter change approach allows the firewall to maintain simple operation while adapting security levels to match the trustworthiness of the network context.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If firewall exceptions are enabled for services on home networks, then adaptability is improved, but security is worsened when connecting to unprotected public networks

Engineering Contradiction:
Improvefirewall exception configurationVSAvoidmalicious access vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The firewall system applies different security qualities to different network contexts. Exceptions are permitted on private home networks where trust is assumed, but blocked on public networks where malicious access is a concern. This local quality approach allows the system to maintain adaptability for legitimate use cases while preventing harmful factors in inappropriate contexts.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system takes preliminary action by detecting the network type before allowing connections. When a public network is detected, the firewall proactively blocks exceptions before malicious access can occur. This preliminary anti-action prevents the vulnerability from arising in the first place, maintaining adaptability for private networks while preemptively countering security risks on public networks.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If a network aware firewall dynamically modifies security parameters, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improvefirewall security protectionVSAvoidfirewall system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The firewall system performs self-service by automatically detecting network type and adjusting security parameters without user intervention. The system monitors its own operating context and autonomously modifies exception rules based on detected network characteristics. This self-service capability improves security through dynamic adaptation while minimizing the complexity burden on users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback by continuously monitoring network connection status and using this information to adjust firewall rules. The detection mechanism provides feedback about the network environment, which automatically triggers appropriate security parameter modifications. This feedback loop enables improved security through context-awareness while keeping the system architecture relatively simple through automated closed-loop control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8321927B2Network aware firewall
Publication Date: 2012.11.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8321927B2 patent drawing
  • US8321927B2 patent drawing
  • US8321927B2 patent drawing

AI summary

Among other things, one or more systems and/or methods for a network aware firewall are disclosed. A method comprises accessing a first network connection from a client computer system and determining whether the first network connection is a first network type or a second network type. The method further comprises dynamically modifying security parameters associated with a firewall local to the client computer system in response to determining whether the network connection is the first network type or the second network type.