Firewall Policy Rule Management with Precomputed Host Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing millions of network firewall policies across a large number of hosts in an enterprise is challenging due to dynamic host lists, installation issues, and diagnosing problems caused by policy updates, especially in environments with thousands of virtual machines and servers.
Innovation Solution
A system and method that updates network policies by determining a subset of hosts based on categories like time zones, precomputes relevant policies, and uses a shared file system to distribute and store policies, allowing for scalability and transparency, with mechanisms to diagnose issues by comparing policy differences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Stability of the object's composition
If firewall policies are updated for all hosts simultaneously, then policy consistency is improved, but system complexity and installation time increase
Solution Approach 1:
The patent segments hosts into multiple subsets based on categories such as time zones, allowing firewall policies to be updated in manageable groups rather than simultaneously across all hosts. This reduces system complexity while maintaining policy consistency within each subset.
Solution Approach 2:
The system precomputes firewall policies for each host before installation. By determining and preparing policies in advance for each host in a subset, the system reduces installation time and complexity during the actual policy deployment phase.
2Stability of the object's composition
If firewall policies are updated for all hosts simultaneously, then policy consistency is improved, but installation time increases
Solution Approach 1:
By dividing hosts into multiple subsets based on categories like time zones, the system can update policies in parallel across different subsets, significantly reducing total installation time while maintaining consistency within each subset.
Solution Approach 2:
Policies are precomputed and prepared in advance for each host before the actual installation. This preliminary computation allows the installation process to proceed more quickly by simply copying pre-prepared policies rather than computing them during installation.
3Reliability
If detailed firewall policies are installed on each host, then network security is improved, but device complexity and management difficulty increase
Solution Approach 1:
The patent introduces a centralized firewall management system as an intermediary between security policy definition and host implementation. This intermediary system handles the complexity of managing detailed policies across all hosts, while individual hosts simply receive and apply the precomputed policies without needing to manage the complexity themselves.
Solution Approach 2:
Detailed firewall policies are precomputed and prepared in advance by the centralized management system for each host. This preliminary action transfers the management complexity from individual hosts to the centralized system, allowing hosts to simply install pre-prepared policies while maintaining comprehensive security.
4Adaptability or versatility
If real-time policy updates are implemented, then network security responsiveness is improved, but system complexity and resource consumption increase
Solution Approach 1:
The system precomputes firewall policies in advance based on current network conditions and host requirements. This preliminary computation allows the system to respond quickly to security changes by simply updating and redistributing pre-computed policies rather than computing them in real-time during deployment.
Solution Approach 2:
By segmenting hosts into subsets and updating policies in batches, the system can implement timely security updates without overwhelming individual hosts or the management system with real-time processing of all hosts simultaneously, reducing overall system complexity.
Data Source
AI summary
A system and method for updating network policies may include determining, from a set of hosts, a subset of hosts to have network policies updated; for each host in the subset of hosts, determining a set of policies relevant to the host, and determining a difference between the set of policies relevant to the host and a set of policies relevant to the host determined at an earlier time; and for each of the subset of hosts, installing the set of policies relevant to the host. The difference may be calculated or determined by comparing a file containing the set of policies relevant to the host, and a file containing the set of policies relevant to the host determined at an earlier time, e.g. determined the prior calendar day.


