Network Filtering Rule Simulator for Security Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring network filtering rules in information handling systems is challenging due to limited knowledge of network administrators about applications and traffic types, often resulting in overly open rules that compromise security and require lengthy lead times for changes, leading to potential misconfigurations and downtime.

Innovation Solution

A system and method for evaluating and configuring network filtering rules using a simulator to predict the effects of rule changes by comparing accepted and rejected network events, allowing for refinement of rules to prevent unwanted traffic and maintain security while minimizing downtime.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network filtering rules are configured manually by administrators, then security can be maintained, but the process is time-consuming and error-prone

Engineering Contradiction:
ImprovesecurityVSAvoidlead time for changes
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a virtual copy of the network filtering system that includes a virtualized network filter and virtualized network events. This virtual copy allows simulation and testing of rule changes without affecting the actual production system, enabling rapid configuration testing and reducing the time required for safe rule deployment.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary simulation of network filtering rule changes before implementing them in the actual network. By pre-testing rules in the virtual environment and comparing simulated results with actual network events, the system validates rule correctness beforehand, preventing errors and reducing adjustment lead times.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network filtering rules are made more stringent to improve security, then unwanted traffic is blocked, but legitimate traffic may be blocked causing downtime

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a feedback mechanism where the virtualized network filter compares simulated filtering results against actual network events. This feedback loop allows the system to learn from real network behavior and adjust virtual filter rules to accurately distinguish between legitimate and unwanted traffic, preventing both security breaches and unnecessary blocking of legitimate traffic.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

By maintaining a virtual copy of the network filter and events, the system can safely test stringent security rules in isolation. The virtual environment allows experimentation with strict filtering without risking disruption to actual network operations, enabling optimization of security settings that balance protection with functionality.

Inventive Principle:
Principle #26Copying

3Ease of operation

If network administrators have limited knowledge of applications and traffic types, then configuration is simpler, but rules become overly open compromising security

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system provides self-service capabilities by automatically generating virtualized network events from actual network traffic and comparing them against proposed filtering rules. This automated process reduces the need for administrators to manually analyze complex traffic patterns, while still achieving secure and accurate rule configuration through computer-generated insights.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The virtualized network filter acts as an intermediary between network administrators and the actual network traffic. It translates complex traffic patterns into simplified virtual events that can be easily processed and compared against filtering rules, making the configuration process simpler while maintaining high security through automated analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10659498B2Systems and methods for security configuration
Publication Date: 2020.05.19 SECUREWORKS CORP
  • US10659498B2 patent drawing
  • US10659498B2 patent drawing
  • US10659498B2 patent drawing

AI summary

A method of configuring a network security device includes receiving a changed set of network rules to replace a current set of network rules; using a plurality of network traffic events to perform a first simulation of according to the current set of network rules and a second simulation according to the changed set of network rules; comparing the results of the first and second simulation to identify changes in network traffic allowed and denied between the current set and the changed set of network rules; displaying the changes in allowed and denied traffic for review of the changed set of network rules; receiving an instruction to implement the changed set of network rules based on the review; and filtering network traffic according to the changed set of network rules.