Post-Installation Port Control for Expanded Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing systems face challenges in flexibly controlling ports used by expanded applications (APs) installed post hoc, leading to difficulties in maintaining appropriate security policies, especially when firewall functions are involved.
Innovation Solution
An information processing apparatus with a storage unit for policy settings, an installation unit for analyzing installed applications, and a setting unit for generating and editing port control information to ensure secure port management, allowing for reliable opening and closing of ports based on security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If port control is performed based on pre-installed services only, then security policy can be maintained for default services, but it becomes difficult to flexibly control ports of expanded applications installed post hoc
Solution Approach 1:
The patent applies preliminary action by analyzing the expanded application's executable file and extracting port information immediately upon installation, before the application begins operations. This allows the system to proactively configure firewall rules and port control settings in advance, ensuring security policies are established before any potential security risks can arise from the new application's network activities.
Solution Approach 2:
The system implements self-service by automatically analyzing the expanded application's binary executable, extracting port information through static analysis, and generating appropriate port control settings without requiring manual user input. The analysis unit autonomously identifies port usage patterns and the setting unit automatically configures the firewall rules, enabling the system to adapt to new applications independently.
2Adaptability or versatility
If firewall function is used to control arbitrary ports, then port control capability is enhanced, but it becomes difficult to determine in advance the port to be used by expanded application
Solution Approach 1:
The system performs preliminary analysis of the expanded application's executable file to extract port information before the application is fully operational. By conducting static analysis on the binary code and resource files, the system determines which ports the application will use in advance, allowing immediate configuration of firewall rules without waiting for runtime observation or manual user specification.
Solution Approach 2:
The patent replaces manual mechanical processes (manual firewall rule configuration and port identification) with automated computational analysis. The analysis unit uses computer-based static analysis techniques to examine the expanded application's executable file, automatically extracting port information and generating control settings, thereby eliminating the time-consuming manual processes of identifying ports and configuring firewall rules.
3Reliability
If manual setting of firewall rules is required, then precise control over network communication is possible, but it increases the complexity of operation and time required for configuration
Solution Approach 1:
The system implements self-service by automatically analyzing the expanded application's executable file and generating appropriate port control settings without requiring manual user input. The analysis unit autonomously identifies port usage patterns by examining the binary code, and the setting unit automatically configures the firewall rules, enabling the system to adapt to new applications independently without operator intervention.
Solution Approach 2:
The patent replaces manual mechanical processes (manual firewall rule configuration and port identification) with automated computational analysis. The analysis unit uses computer-based static analysis techniques to examine the expanded application's executable file, automatically extracting port information and generating control settings, thereby eliminating the time-consuming manual processes of identifying ports and configuring firewall rules.
Data Source
AI summary
When an expanded application (AP) is installed, an information processing apparatus analyzes port control information relating to a unique port to be used by the expanded AP and edits policy setting items including existing policy setting items based on the port control information. Then, the information processing apparatus receives setting input via the edited policy setting items and generates setting information. The information processing apparatus applies a filtering rule to a firewall (FW) unit according to the setting information, whereby the security is maintained in the case where the expanded AP is installed.


