Automated Security Rule Amendment for Network Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing security rule-sets in complex network architectures is increasingly challenging, as existing systems struggle to efficiently update and enforce security policies across multiple security gateways, leading to inefficiencies and potential security vulnerabilities.

Innovation Solution

An automated method and system for managing security rule-sets at security gateways, which involves obtaining data on unfitting connectivity requests, searching for and generating amendments to existing rules, and implementing these amendments to facilitate allowed traffic while minimizing extra allowed or restricted traffic, using predefined criteria to select the best matching rules for amendment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual management of security rule-sets is used in complex network architectures, then security policies can be enforced at security gateways, but the complexity of updating and enforcing security policies increases significantly

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidrule-set management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated self-service management of security rule-sets. The processor automatically receives connectivity requests, determines rule violations, generates amendments, and implements updates across security gateways without manual intervention. This automation resolves the contradiction by maintaining reliable security enforcement while eliminating the complexity of manual rule-set management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by proactively analyzing connectivity requests against existing security rules before violations occur. The processor pre-determines potential rule violations and automatically generates amendment recommendations in advance, allowing security policies to be updated before issues arise, thus maintaining reliability while reducing management complexity.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated rule amendment is implemented, then connectivity requests can be facilitated efficiently, but there is a risk of allowing extra traffic or restricting legitimate traffic

Engineering Contradiction:
Improveconnectivity request processing efficiencyVSAvoidtraffic control accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanisms by continuously monitoring the effects of rule amendments. The processor receives connectivity requests, applies amendments, and tracks whether the amendments achieve their intended purpose without creating unintended consequences. This feedback loop ensures that automated rule amendments maintain both efficiency and accuracy in traffic control.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies partial actions by making targeted, minimal amendments to security rules rather than comprehensive changes. The processor identifies specific rule violations and generates amendments that address only the necessary portions, reducing the risk of unintended traffic restrictions or allowances while maintaining processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multiple security gateways are deployed to enforce security policies, then network security is strengthened, but the difficulty of managing and synchronizing rules across gateways increases

Engineering Contradiction:
Improvenetwork securityVSAvoidrule-set management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges the management of security rules across multiple gateways into a unified automated process. The processor receives connectivity requests and automatically determines and implements rule amendments across all relevant security gateways simultaneously, eliminating the need for separate manual management of each gateway while maintaining strong network security through consistent rule enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9203808B2Method and system for management of security rule set
Publication Date: 2015.12.01 TUFIN SOFTWARE TECH
  • US9203808B2 patent drawing
  • US9203808B2 patent drawing
  • US9203808B2 patent drawing

AI summary

There are provided a method of automated managing an ordered set of security rules implemented at a plurality of security gateways and a system thereof. The method comprises obtaining data characterizing a connectivity request which may become allowable only upon changes of an initial rule-set, thus giving rise to an unfitting connectivity request; analyzing routing tables of the plurality of the security gateways; generating ranking the security gateways in accordance with their relevance to the unfitting connectivity request; selecting one or more security gateways with the highest ranking; and implementing a configuration change required in order to facilitate allowance of the unfitting connectivity request at the one or more selected security gateways.