Object-Oriented Policy Configuration for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As network devices provide increasingly complex functions, configuring and managing their policies becomes increasingly complex, leading to performance issues, network errors, and security vulnerabilities due to improper configuration, with a need for structured policy expressions and efficient processing of policies, especially in handling undefined policy scenarios.
Innovation Solution
The development of a system and method for configuring and evaluating object-oriented policies that allow users to specify structured policies for network devices, enabling efficient processing of complex data streams, controlling policy execution order, and defining actions for undefined policy elements, using a configuration interface that identifies object classes, members, and actions within packet streams.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network devices provide increasingly complex functions, then device functionality and versatility improve, but configuration complexity and difficulty increase
Solution Approach 1:
The patent transforms policy configuration from a complex, manual process into a structured, parameter-driven system. By introducing object-oriented policy expressions with defined parameters (object class, member, action), the system allows complex network functions to be configured through standardized parameters rather than ad-hoc settings, reducing configuration complexity while maintaining functional versatility.
Solution Approach 2:
The patent segments policy configuration into distinct, manageable components: object class identification, member specification, and action definition. This segmentation allows administrators to configure complex network functions by assembling predefined policy templates rather than creating configurations from scratch, thereby reducing the perceived complexity while maintaining adaptability.
2Adaptability or versatility
If the number of policies increases to handle complex functions, then policy coverage and functionality improve, but processing overhead and evaluation time increase
Solution Approach 1:
The patent implements preliminary action by pre-defining object classes, members, and actions that can be reused across multiple policies. Instead of evaluating entirely new policies each time, the system references pre-validated policy templates and expressions, significantly reducing evaluation time while maintaining comprehensive policy coverage for complex network functions.
Solution Approach 2:
The patent enables copying of policy expressions and templates across multiple policy instances. Once a policy expression is defined with specific object classes, members, and actions, it can be replicated and referenced by multiple policies, reducing the overall number of unique policy evaluations needed while maintaining comprehensive coverage.
3Reliability
If policies are made more specific to handle undefined scenarios, then policy precision and reliability improve, but policy complexity and administrative overhead increase
Solution Approach 1:
The patent introduces an intermediary layer between policy definition and execution: the object-oriented expression framework. This intermediary provides a standardized structure (object class, member, action) that mediates between high-level policy intent and low-level implementation details, allowing specific handling of undefined scenarios without increasing apparent policy complexity for administrators.
Data Source
AI summary
Systems and methods for configuring and evaluating policies that direct processing of one or more data streams are described. A configuration interface is described for allowing users to specify object oriented policies. These object oriented policies may allow any data structures to be applied with respect to a payload of a received packet stream, including any portions of HTTP traffic. A configuration interface may also allow the user to control the order in which policies and policy groups are executed, in addition to specifying actions to be taken if one or more policies are undefined. Systems and methods for processing the policies may allow efficient processing of object-oriented policies by applying potentially complex data structures to unstructured data streams. A device may also interpret and process a number of flow control commands and policy group invocation statements to determine an order of execution among a number of policies and policy groups. These policy configurations and processing may allow configuration and processing of complex network behaviors relating to load balancing, VPNs, SSL offloading, content switching, application security, acceleration, and caching.


