Security Device Controller for Heterogeneous Network Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of managing and configuring firewall rules and routing access control lists (ACLs) across heterogeneous networks, with thousands of entries, leads to performance and security issues due to poorly defined rule bases and configuration mistakes, requiring efficient management tools to track changes and ensure compliance across multiple devices.

Innovation Solution

A security device controller that receives configuration policies in a vendor-neutral language, automatically configures multiple security devices, including physical, virtual, and software-defined networks, translates policies into vendor-specific formats, and provides reporting and analytics to manage and optimize firewall and router configurations, facilitating efficient and unified policy management across diverse network environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration and management of firewall rules and routing ACLs is performed across heterogeneous networks, then configuration flexibility and device-specific optimization are maintained, but complexity of management and risk of configuration errors increase significantly

Engineering Contradiction:
Improveease of configuration managementVSAvoidcomplexity of managing thousands of rules
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a centralized configuration management system that acts as an intermediary between administrators and multiple security devices. This system provides a unified interface for managing firewall rules and ACLs across heterogeneous networks, automatically translating high-level policies into device-specific configurations, thereby reducing management complexity while maintaining configuration flexibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The configuration management system is designed to be universal, supporting multiple vendors and device types through a single platform. It can manage thousands of rules across different security devices simultaneously, providing multi-functional capabilities including policy translation, configuration deployment, and compliance verification in one integrated system

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive firewall rules and ACLs are implemented to secure data center and enterprise networks, then security hardening is improved, but complexity of rule logic and configuration management increases

Engineering Contradiction:
Improvesecurity hardeningVSAvoidcomplexity of rule logic
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex security policy into hierarchical layers and modular components. By dividing the rule base into manageable segments organized by function, location, and priority, the system maintains comprehensive security coverage while reducing the perceived complexity for administrators through structured policy organization

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The configuration management system serves as an intermediary that handles the complexity of rule logic internally. It translates high-level security intentions into detailed device-specific rules, allowing administrators to focus on security requirements rather than complex rule syntax and logic across multiple vendors

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If extensive rule lists with thousands of entries are maintained for network security, then security coverage is improved, but difficulty of tracking change management and monitoring increases

Engineering Contradiction:
Improvesecurity coverageVSAvoiddifficulty of tracking change management
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements automated feedback mechanisms that continuously monitor and report on configuration changes across the rule base. The system tracks modifications, validates changes against security policies, and provides real-time feedback on compliance status, making change management transparent and manageable even with thousands of rules

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The centralized management system acts as an intermediary that consolidates visibility into all rule changes across heterogeneous devices. It provides unified reporting and analytics on configuration state, enabling administrators to track and audit changes systematically without manually monitoring each device individually

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9749361B2Security device controller
Publication Date: 2017.08.29 INFOBLOX INC
  • US9749361B2 patent drawing
  • US9749361B2 patent drawing
  • US9749361B2 patent drawing

AI summary

In some embodiments, a security device controller (SDC) is provided. In some embodiments, a security device controller includes receiving a configuration policy in a vendor neutral language; and automatically configuring a plurality of security devices on a heterogeneous network based on the configuration policy. For example, the plurality of security devices can include physical, virtual, or software defined network (SDN) based routers and/or firewalls, and the heterogeneous network can include security devices from a plurality of different vendors.