Firewall Policy Rule Management with Precomputed Host Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing millions of network firewall policies across a large number of hosts in an enterprise is challenging due to dynamic host lists, installation issues, and diagnosing problems caused by policy updates, especially in environments with thousands of virtual machines and servers.

Innovation Solution

A system and method that updates network policies by determining a subset of hosts based on categories like time zones, precomputes relevant policies, and uses a shared file system to distribute and store policies, allowing for scalability and transparency, with mechanisms to diagnose issues by comparing policy differences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Stability of the object's composition

If firewall policies are updated for all hosts simultaneously, then policy consistency is improved, but system complexity and installation time increase

Engineering Contradiction:
Improvepolicy consistencyVSAvoidsystem complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent segments hosts into multiple subsets based on categories such as time zones, allowing firewall policies to be updated in manageable groups rather than simultaneously across all hosts. This reduces system complexity while maintaining policy consistency within each subset.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system precomputes firewall policies for each host before installation. By determining and preparing policies in advance for each host in a subset, the system reduces installation time and complexity during the actual policy deployment phase.

Inventive Principle:
Principle #10Preliminary action

2Stability of the object's composition

If firewall policies are updated for all hosts simultaneously, then policy consistency is improved, but installation time increases

Engineering Contradiction:
Improvepolicy consistencyVSAvoidinstallation time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

By dividing hosts into multiple subsets based on categories like time zones, the system can update policies in parallel across different subsets, significantly reducing total installation time while maintaining consistency within each subset.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Policies are precomputed and prepared in advance for each host before the actual installation. This preliminary computation allows the installation process to proceed more quickly by simply copying pre-prepared policies rather than computing them during installation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If detailed firewall policies are installed on each host, then network security is improved, but device complexity and management difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized firewall management system as an intermediary between security policy definition and host implementation. This intermediary system handles the complexity of managing detailed policies across all hosts, while individual hosts simply receive and apply the precomputed policies without needing to manage the complexity themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Detailed firewall policies are precomputed and prepared in advance by the centralized management system for each host. This preliminary action transfers the management complexity from individual hosts to the centralized system, allowing hosts to simply install pre-prepared policies while maintaining comprehensive security.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If real-time policy updates are implemented, then network security responsiveness is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity responsivenessVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system precomputes firewall policies in advance based on current network conditions and host requirements. This preliminary computation allows the system to respond quickly to security changes by simply updating and redistributing pre-computed policies rather than computing them in real-time during deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By segmenting hosts into subsets and updating policies in batches, the system can implement timely security updates without overwhelming individual hosts or the management system with real-time processing of all hosts simultaneously, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12407654B2System and method for firewall policy rule management
Publication Date: 2025.09.02 MORGAN STANLEY SERVICES GROUP INC
  • US12407654B2 patent drawing
  • US12407654B2 patent drawing
  • US12407654B2 patent drawing

AI summary

A system and method for updating network policies may include determining, from a set of hosts, a subset of hosts to have network policies updated; for each host in the subset of hosts, determining a set of policies relevant to the host, and determining a difference between the set of policies relevant to the host and a set of policies relevant to the host determined at an earlier time; and for each of the subset of hosts, installing the set of policies relevant to the host. The difference may be calculated or determined by comparing a file containing the set of policies relevant to the host, and a file containing the set of policies relevant to the host determined at an earlier time, e.g. determined the prior calendar day.