Object-Oriented Policy Configuration for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As network devices provide increasingly complex functions, configuring and managing their policies becomes increasingly complex, leading to performance issues, network errors, and security vulnerabilities due to improper configuration, with a need for structured policy expressions and efficient processing of policies, especially in handling undefined policy scenarios.

Innovation Solution

The development of a system and method for configuring and evaluating object-oriented policies that allow users to specify structured policies for network devices, enabling efficient processing of complex data streams, controlling policy execution order, and defining actions for undefined policy elements, using a configuration interface that identifies object classes, members, and actions within packet streams.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network devices provide increasingly complex functions, then device functionality and versatility improve, but configuration complexity and difficulty increase

Engineering Contradiction:
Improvedevice functionalityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms policy configuration from a complex, manual process into a structured, parameter-driven system. By introducing object-oriented policy expressions with defined parameters (object class, member, action), the system allows complex network functions to be configured through standardized parameters rather than ad-hoc settings, reducing configuration complexity while maintaining functional versatility.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments policy configuration into distinct, manageable components: object class identification, member specification, and action definition. This segmentation allows administrators to configure complex network functions by assembling predefined policy templates rather than creating configurations from scratch, thereby reducing the perceived complexity while maintaining adaptability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the number of policies increases to handle complex functions, then policy coverage and functionality improve, but processing overhead and evaluation time increase

Engineering Contradiction:
Improvepolicy coverageVSAvoidpolicy evaluation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining object classes, members, and actions that can be reused across multiple policies. Instead of evaluating entirely new policies each time, the system references pre-validated policy templates and expressions, significantly reducing evaluation time while maintaining comprehensive policy coverage for complex network functions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables copying of policy expressions and templates across multiple policy instances. Once a policy expression is defined with specific object classes, members, and actions, it can be replicated and referenced by multiple policies, reducing the overall number of unique policy evaluations needed while maintaining comprehensive coverage.

Inventive Principle:
Principle #26Copying

3Reliability

If policies are made more specific to handle undefined scenarios, then policy precision and reliability improve, but policy complexity and administrative overhead increase

Engineering Contradiction:
Improvepolicy definition completenessVSAvoidpolicy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer between policy definition and execution: the object-oriented expression framework. This intermediary provides a standardized structure (object class, member, action) that mediates between high-level policy intent and low-level implementation details, allowing specific handling of undefined scenarios without increasing apparent policy complexity for administrators.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7870277B2Systems and methods for using object oriented expressions to configure application security policies
Publication Date: 2011.01.11 CITRIX SYSTEMS INC
  • US7870277B2 patent drawing
  • US7870277B2 patent drawing
  • US7870277B2 patent drawing

AI summary

Systems and methods for configuring and evaluating policies that direct processing of one or more data streams are described. A configuration interface is described for allowing users to specify object oriented policies. These object oriented policies may allow any data structures to be applied with respect to a payload of a received packet stream, including any portions of HTTP traffic. A configuration interface may also allow the user to control the order in which policies and policy groups are executed, in addition to specifying actions to be taken if one or more policies are undefined. Systems and methods for processing the policies may allow efficient processing of object-oriented policies by applying potentially complex data structures to unstructured data streams. A device may also interpret and process a number of flow control commands and policy group invocation statements to determine an order of execution among a number of policies and policy groups. These policy configurations and processing may allow configuration and processing of complex network behaviors relating to load balancing, VPNs, SSL offloading, content switching, application security, acceleration, and caching.