Automated Security Gateway Rule-Set Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring security gateways, especially in complex network architectures, requires significant manual effort and prior knowledge of IT resources and connectivity requirements, necessitating a more automated approach for rule-set creation.

Innovation Solution

An automated method and system for configuring security gateways that involves setting up an initial rule-set, collecting log records, transforming them into operational rules, and processing these rules to generate an optimized rule-set, reducing human involvement and errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual configuration of security gateway rule-set is performed, then configuration accuracy can be maintained through expert knowledge, but significant time and human effort are required

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The security gateway automatically generates its own rule-set by analyzing collected log records without requiring manual configuration by security experts. The system serves itself by transforming operational logs into optimized security rules, eliminating the time-consuming manual configuration process while maintaining accuracy through automated analysis of actual traffic patterns

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system collects log records during an initial monitoring period before generating the rule-set. This preliminary data collection phase allows the automated system to learn actual network traffic patterns and connectivity requirements, enabling accurate rule-generation without requiring prior expert knowledge of the network architecture

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated rule-set generation is implemented, then configuration time is reduced, but prior knowledge of network resources and topology is required

Engineering Contradiction:
Improveconfiguration speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system continuously collects log records from the security gateway's operational traffic and uses this feedback to automatically generate and optimize the rule-set. By analyzing actual traffic patterns, connectivity requirements, and resource interactions captured in the logs, the system adapts to the specific network architecture without requiring pre-programmed knowledge of network topology

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Log records serve as an intermediary that bridges the gap between automated processing and network-specific knowledge. Instead of requiring direct expert input about network resources and topology, the system processes intermediate log data that naturally encodes this information, transforming operational evidence into security rules

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive log collection is performed, then rule-generation accuracy improves, but storage and processing requirements increase

Engineering Contradiction:
Improverule-generation accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the essential information needed for rule-generation from the collected log records, such as source and destination addresses, ports, protocols, and traffic patterns. By selectively extracting relevant features rather than processing all raw log data, the system achieves accurate rule-generation while minimizing storage and computational requirements

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8490171B2Method of configuring a security gateway and system thereof
Publication Date: 2013.07.16 TUFIN SOFTWARE TECH
  • US8490171B2 patent drawing
  • US8490171B2 patent drawing
  • US8490171B2 patent drawing

AI summary

There is provided a rule-set generator and a method of automated configuration of a security gateway. The method comprises setting-up an initial rule-set; obtaining log records of communication events corresponding to the initial rule-set so as to obtain a sufficient amount of log records; transforming the obtained log records into respective rules, wherein source, destination and service fields in each rule correspond to source, destination and service values in respective obtained log record, and the action in all rules is defined as “Accept”, thus giving rise to a transformation-based rule-set; and processing the transformation-based rule-set so as to generate an operable rule-set by processing the transformation-based rule-set.