Template-Aware Service Rule Processing Engine for Cloud Firewall Scalability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing enterprise firewall policy model is inadequate for supporting private cloud and automation scenarios, leading to rule and dynamic group overload, scalability issues, and management complexity due to its inability to handle hundreds of application instances created from the same template, resulting in frequent rule changes and management challenges.
Innovation Solution
Introducing cloud template awareness in the service policy framework with service rule processing engines that support template-specific dynamic groups and rules, allowing for dynamic security tags and seamless association of data compute nodes with dynamic component groups, enabling efficient processing of service rules defined in terms of template identifiers and match criteria.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional enterprise firewall policy model is used to support private cloud scenarios, then instance isolation and security can be maintained, but rule and dynamic group overload occurs due to hundreds of template instances
Solution Approach 1:
The patent applies universality by creating a single template-based firewall rule that can be universally applied to multiple template instances. Instead of creating separate firewall rules for each of the hundreds of instances, the system defines a universal template rule that automatically applies to all instances derived from that template, thereby maintaining instance isolation while avoiding rule overload.
Solution Approach 2:
The patent merges multiple instance-specific rules into a single template-level rule. By combining the security requirements of hundreds of individual instances into one unified template rule, the system maintains the necessary instance isolation and security boundaries while dramatically reducing the total number of firewall rules from tens of thousands to a manageable few hundred.
2Reliability
If separate firewall rules are created for each template instance, then specific security expectations can be met, but scalability and performance issues arise
Solution Approach 1:
The system creates universal template-based firewall rules that fulfill specific security expectations for entire classes of instances. A single template rule with qualifiers can enforce security policies across multiple instances simultaneously, allowing the system to scale to hundreds of instances without proportionally increasing the number of firewall rules, thereby maintaining both security and scalability.
3Adaptability or versatility
If firewall rules are created and modified for each template instantiation, then instance-specific security can be enforced, but rule and dynamic group churn overwhelms policy management systems
Solution Approach 1:
The patent implements universality by enabling template-level firewall rule management that automatically applies to all instances. When a template rule is created or modified, the changes are automatically propagated to all current and future instances derived from that template. This eliminates the need for individual instance rule management, reducing policy churn from tens of thousands of changes to a manageable number of template-level changes.
Solution Approach 2:
The system performs preliminary action by pre-defining firewall rules at the template level before instances are created. This allows security policies to be established in advance for entire instance families, so when instances are instantiated, they automatically inherit the appropriate firewall rules without requiring separate rule creation or modification for each instance.
4Ease of manufacture
If template instances are deleted, then resource cleanup occurs, but firewall rules are often overlooked and not deleted
Solution Approach 1:
The system applies universality by maintaining a hierarchical relationship where firewall rules are defined at the template level rather than the instance level. When template instances are deleted, the system automatically tracks this through the template-instance relationship and can automatically remove or deactivate associated firewall rules. This eliminates the manual oversight problem where administrators forget to delete rules for deleted instances.
Solution Approach 2:
The patent implements feedback mechanisms that automatically monitor template-instance relationships. When instances are deleted, the system receives feedback about the changed state and automatically updates or removes the corresponding firewall rules. This closed-loop feedback system ensures that firewall rule management remains synchronized with actual instance deployment states without requiring manual intervention.
Data Source
AI summary
Some embodiments of the invention introduce cloud template awareness in the service policy framework. Some embodiments provide one or more service rule processing engines that natively support (1) template-specific dynamic groups and template-specific rules, and (2) dynamic security tag concepts. A service rule processing engine of some embodiments natively supports template-specific dynamic groups and rules as it can directly process service rules that are defined in terms of dynamic component groups, template identifiers, template instance identifiers, and/or template match criteria. Examples of such services can include any kind of middlebox services, such as firewalls, load balancers, network address translators, intrusion detection systems, intrusion prevention systems, etc.


