OWL-Based Security Audit System for Firewall Rule Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual auditing of firewall rules is labor-intensive, time-consuming, and prone to human errors, often occurring after a security breach, and fails to detect complex misconfigurations or anomalous behavior in large networks with changing security threats.

Innovation Solution

A system that converts security policies into Web Ontology Language (OWL)-based rules and log records into OWL format, using Semantic Web Rule Language (SWRL) statements to identify potential security breaches by applying OWL reasoners to the formatted data, facilitating intelligent auditing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual auditing methods are used to check firewall rules, then human operators can identify security issues, but the process becomes labor-intensive and time-consuming

Engineering Contradiction:
Improvesecurity audit accuracyVSAvoidauditing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical auditing processes with an automated computer-based system that uses machine learning models and algorithms to analyze firewall rules, configuration files, and security policies. This substitution eliminates human labor while maintaining or improving detection accuracy through consistent, rule-based automated analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service auditing by automatically collecting security configuration data, applying analysis algorithms, generating audit reports, and identifying violations without requiring human intervention. The automated system serves itself by continuously monitoring and auditing security configurations as they change.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual auditing is performed after a security breach, then remediation can be initiated, but the response time is delayed

Engineering Contradiction:
Improvesecurity enforcementVSAvoidremediation speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements preliminary action by continuously auditing firewall rules and security configurations before security breaches occur. The system proactively identifies misconfigurations, policy violations, and potential security gaps in advance, enabling organizations to remediate issues before they lead to actual security incidents rather than reacting after breaches occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous auditing of security configurations through automated processes that operate constantly without interruption. This continuous monitoring ensures that security policies are consistently enforced and violations are detected immediately as they occur, maintaining uninterrupted security protection rather than periodic manual checks.

Inventive Principle:
Principle #20Continuity of useful action

3Difficulty of detecting and measuring

If conventional auditing methods are used, then simple rule violations can be detected, but complex misconfigurations and anomalous behavior remain undetected

Engineering Contradiction:
Improvedetection capabilityVSAvoidsecurity breach information
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent applies parameter changes by transforming security audit analysis from simple rule-matching to multi-dimensional analysis using machine learning models. The system analyzes multiple parameters simultaneously including traffic patterns, temporal behavior, source-destination relationships, and configuration contexts, enabling detection of complex misconfigurations that single-parameter conventional methods cannot identify.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system uses composite analysis by combining multiple detection approaches including rule-based validation, machine learning anomaly detection, pattern recognition, and correlation analysis. This composite methodology integrates different analytical techniques to detect complex security issues that individual methods would miss, similar to how composite materials combine different properties to achieve superior performance.

Inventive Principle:
Principle #40Composite materials

4Reliability

If firewall rules are manually configured to satisfy security policies, then security requirements can be met, but the complexity increases with more policies

Engineering Contradiction:
Improvepolicy complianceVSAvoidfirewall rule complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual firewall rule configuration with automated systems that use machine learning models to generate, optimize, and manage firewall rules. The system automatically analyzes security policies, network traffic patterns, and configuration data to produce optimized rule sets, eliminating the need for manual configuration while ensuring policy compliance and reducing rule complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system applies parameter changes by transforming firewall rule management from static, manually-configured rules to dynamic, algorithmically-generated rules that adapt to changing security conditions. The machine learning models continuously optimize rule parameters based on analyzed data, automatically simplifying rule sets while maintaining security effectiveness as policies evolve.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9369478B2OWL-based intelligent security audit
Publication Date: 2016.06.14 VMWARE INC
  • US9369478B2 patent drawing
  • US9369478B2 patent drawing
  • US9369478B2 patent drawing

AI summary

The disclosure herein describes a system for facilitating intelligent auditing of security log records. A set of security policies are converted into a set of web ontology language (OWL)-based rules. At the same time, log records are also converted into an OWL-based format. The system then applies the OWL-based rules, which can be in the form of a number of semantic web rule language (SWRL) statements, to the OWL-formatted log data. As a result, the system can identify potential security breaches which cannot be easily identified by conventional auditing methods.