Network Controller Address Grouping for Distributed Firewall Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In software-defined data centers with virtualized networks, efficiently implementing distributed firewall rules across a large number of network devices is challenging due to the need for numerous firewall rules, which requires optimized configuration and minimization of rule changes to reduce resource usage and churn.
Innovation Solution
A network controller optimizes configuration data for flow-based managed forwarding elements by assigning priorities to distributed service rules, using non-overlapping address sets, and employing conjunctive matching techniques to minimize the number of flow entries, while also normalizing address sets to reduce the complexity of rule implementation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If distributed firewall rules are implemented across many network devices, then network security coverage is improved, but the number of flow entries and configuration complexity increases significantly
Solution Approach 1:
The patent segments the large set of distributed service rules into multiple rule sets organized by priority levels. Each rule set contains rules with similar characteristics or priority ranges, allowing the network controller to manage and push configurations in smaller, organized batches rather than handling all rules simultaneously, thereby reducing configuration complexity while maintaining comprehensive security coverage
Solution Approach 2:
The patent introduces a new dimension of organization by grouping rules into priority-based rule sets and using flattened priority lists. This transforms the flat, unstructured set of firewall rules into a multi-dimensional structure with priority levels and rule set groupings, enabling more efficient management and reduction of flow entries without compromising security coverage
2Adaptability or versatility
If service rules are added or modified in the distributed firewall, then security policy flexibility is improved, but churn and resource usage increase due to re-assignment of priorities
Solution Approach 1:
The patent performs preliminary organization of service rules into priority-based rule sets before they are added to the distributed firewall. By pre-flattening the rule priorities and establishing the priority structure in advance, the system minimizes the need for re-assignment when new rules are added or modified, thereby reducing churn and resource usage while maintaining security policy flexibility
Solution Approach 2:
The patent implements a dynamic priority assignment mechanism where rules are organized into flexible rule sets that can be easily updated. When service rules are added or modified, the system can dynamically adjust the flattened priority list within the existing rule set structure, allowing security policies to be flexible and adaptive without causing significant churn or resource consumption
3Productivity
If priority values are assigned to service rules for flow entry generation, then rule processing efficiency is improved, but the priority space allocation and management complexity increase
Solution Approach 1:
The patent segments the 16-bit priority space into multiple rule sets, with each rule set containing a flattened list of priorities. This segmentation allows the system to assign priority values in an organized manner across different rule sets, improving rule processing efficiency while managing priority space allocation in a structured way that reduces management complexity
Solution Approach 2:
The patent changes the parameter organization by transforming service rules into a flattened priority list structure. This parameter transformation optimizes the priority space utilization and simplifies the assignment process, thereby improving rule processing efficiency while reducing the complexity of priority space management through systematic reorganization
Data Source
AI summary
Some embodiments provide a method for a network controller that manages a flow-based managed forwarding element (MFE). The method receives multiple service rules for implementation by the MFE. Each service rule matches over a set of network addresses. At least one network address is in the set of network addresses for at least two service rules. The method groups the network addresses into non-overlapping groups of network addresses, each of which addresses that are all matched by only a same set of service rules. The method generates flow entries that match over the groups of network addresses for the MFE to use to implement the service rules.


