Automated Security Rule-Set Generation from Network Logs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring security gateways, especially in complex network architectures, requires significant manual effort and prior knowledge of IT resources and connectivity requirements, necessitating an automated method for generating operational rule-sets.

Innovation Solution

An automated method for generating a security rule-set involves obtaining log records of communication events, generating a preliminary rule-set of permissive rules, dividing these rules into non-overlapping sets, and processing them to create an operational rule-set that covers the log records, reducing human involvement and error.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual configuration of security gateway rule-set is performed, then configuration accuracy and security policy compliance are improved, but configuration time and operational complexity increase significantly

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system enables automated self-configuration of security gateway rule-sets by collecting log records from the network environment, analyzing communication patterns, and automatically generating optimized security rules without requiring manual security expert intervention. The automated rule-generation system processes log data to create initial rule-sets that are then refined through iterative optimization.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of network traffic patterns by collecting and processing log records before final rule-set deployment. This preliminary action includes identifying communication patterns, determining security requirements, and pre-generating rule candidates that are later optimized and validated against security policies.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated rule-generation is implemented, then configuration time and operational complexity are reduced, but rule-set optimization and security policy compliance become more challenging

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidrule-set optimization quality
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The system implements dynamic rule-set optimization through iterative processes that continuously refine security rules based on analyzed log records and security requirements. The optimization is dynamic as it adapts to changing network conditions and security threats by processing ongoing log data and updating rule-sets accordingly.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where generated rule-sets are evaluated against security policies and network traffic patterns, with results fed back into the optimization process. This feedback loop enables continuous improvement of rule quality by identifying and correcting suboptimal rules based on actual network behavior and security requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9021549B2Method of generating security rule-set and system thereof
Publication Date: 2015.04.28 TUFIN SOFTWARE TECH
  • US9021549B2 patent drawing
  • US9021549B2 patent drawing
  • US9021549B2 patent drawing

AI summary

There are provided a method of generation of a security rule-set and a system thereof. The method includes: obtaining a group of log records of communication events resulting from traffic related to the security gateway; generating a preliminary rule-set of permissive rules, said set covering the obtained group of log records; generating, with the help of mapping the generated preliminary rule-set to the obtained group of log records, a rule-set of non-overlapping rules covering the group of log records; and generating an operational rule-set by processing the generated rule-set of non-overlapping rules, said processing including mapping the generated rule-set of non-overlapping rule to the obtained group of log records.