Object-Oriented Policy Management for Network Security Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As network devices provide increasingly complex functions, their configuration becomes more intricate, leading to performance decreases, network errors, application incompatibilities, and security weaknesses due to improper or suboptimal settings, with a need for structured policy frameworks that can efficiently process and prioritize policies.

Innovation Solution

The implementation of object-oriented policies that allow users to specify structured expressions for network traffic, enabling efficient processing of complex data streams and defining actions for undefined policy conditions, with a configuration interface that controls policy order and execution in network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number and complexity of network device functions increase, then device functionality and capabilities improve, but configuration complexity and administrative overhead increase

Engineering Contradiction:
Improvedevice functionalityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the policy configuration into hierarchical levels: global defaults, policy groups, and individual policies. This segmentation allows complex network functions to be configured through modular policy units rather than monolithic configuration sets, reducing overall configuration complexity while maintaining full functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action through default policies and default policy groups that are pre-configured with standard security and processing rules. These defaults provide a baseline configuration that reduces administrative overhead, allowing users to override only specific policies rather than configuring everything from scratch.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the number of policies required for configuration increases, then device functionality improves, but processing order specification and policy management complexity increase

Engineering Contradiction:
Improvepolicy functionalityVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple policies into policy groups that can be evaluated and applied collectively. This merging reduces policy management complexity by allowing administrators to manage groups of policies as single units while maintaining the ability to specify processing orders among groups, thereby simplifying the management of large numbers of individual policies.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent establishes preliminary processing orders between policy groups through configuration parameters. This preliminary specification of evaluation order allows the system to automatically determine which policies to apply first, reducing the need for manual policy management and decreasing administrative overhead as the number of policies increases.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If policies are made more specific to handle undefined conditions, then policy accuracy improves, but additional policies and complexity increase

Engineering Contradiction:
Improvepolicy definition accuracyVSAvoidpolicy quantity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces default policies as intermediary elements that handle undefined conditions. These default policies act as mediators between specific policy rules and undefined scenarios, providing fallback behavior without requiring additional specific policies for every possible undefined condition. This maintains policy definition accuracy while avoiding exponential growth in policy quantity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If configuration precision and policy specificity increase, then network security and performance improve, but configuration time and administrative overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action through pre-configured default policies and policy groups that provide immediate security and processing rules. These defaults are established in advance, allowing the system to function securely from deployment without requiring extensive custom configuration. Administrators can then refine specific policies as needed, significantly reducing initial configuration time while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9160768B2Systems and methods for managing application security profiles
Publication Date: 2015.10.13 CITRIX SYSTEMS INC
  • US9160768B2 patent drawing
  • US9160768B2 patent drawing
  • US9160768B2 patent drawing

AI summary

Systems and methods for configuring and evaluating policies that direct processing of one or more data streams are described. A configuration interface is described for allowing users to specify object oriented policies. These object oriented policies may allow any data structures to be applied with respect to a payload of a received packet stream, including any portions of HTTP traffic. A configuration interface may also allow the user to control the order in which policies and policy groups are executed, in addition to specifying actions to be taken if one or more policies are undefined. Systems and methods for processing the policies may allow efficient processing of object-oriented policies by applying potentially complex data structures to unstructured data streams. A device may also interpret and process a number of flow control commands and policy group invocation statements to determine an order of execution among a number of policies and policy groups. These policy configurations and processing may allow configuration and processing of complex network behaviors relating to load balancing, VPNs, SSL offloading, content switching, application security, acceleration, and caching.