Web Application Firewall Policy Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face challenges in implementing effective web application firewall policies due to the need for customized security measures for each web application, leading to watered-down policies that offer inadequate protection and require time-consuming manual programming by skilled developers.

Innovation Solution

A firewall system with a processor that configures widgets for web applications, featuring a security stack with an order of execution for widgets to enable or disable security actions on a per-application basis, including state control and security widgets for behavior analysis, signature detection, and virtual patching, allowing for customizable and efficient security policies without requiring extensive programming.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single firewall policy is applied to all web applications, then policy implementation is simplified, but security protection becomes inadequate due to watered-down rules

Engineering Contradiction:
Improvefirewall policy implementationVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the firewall policy into multiple widgets that can be independently configured and applied to different web applications. Each widget represents a discrete security rule that can be selectively enabled or disabled, allowing customized security policies per application while maintaining centralized management through the security stack.

Inventive Principle:
Principle #1Segmentation

2Reliability

If customized firewall policies are created for each web application, then security protection is enhanced, but policy configuration becomes complex and time-consuming

Engineering Contradiction:
Improvesecurity protectionVSAvoidfirewall policy configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service capabilities through automated widget generation that creates firewall rules based on application fingerprints and security requirements. The system automatically configures widgets for each web application without requiring manual programming, reducing complexity while maintaining customized security policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses parameter changes to dynamically adjust firewall policies based on application-specific parameters such as traffic patterns, security requirements, and application fingerprints. The security stack evaluates these parameters and automatically configures appropriate widgets, enabling customized policies without manual intervention.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If manual programming is used to create firewall rules, then policy customization is achieved, but development time and skill requirements increase

Engineering Contradiction:
Improvepolicy customizationVSAvoidpolicy development time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically generating firewall widgets through application fingerprinting and security requirement analysis. The security stack autonomously creates and configures widgets without requiring skilled programmers, eliminating manual coding while maintaining policy adaptability to each application's specific needs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring security widgets based on application fingerprints and security templates before deployment. The system prepares customized security policies in advance through automated analysis, eliminating the need for manual programming during implementation and reducing both time and skill requirements.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If security widgets are executed in a fixed order, then processing efficiency is improved, but flexibility in security control is reduced

Engineering Contradiction:
Improvetraffic processing efficiencyVSAvoidsecurity control flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by making the widget execution order configurable and adaptable to different security scenarios. The security stack allows widgets to be arranged in different sequences based on application requirements and security priorities, providing both efficient processing through optimized ordering and flexibility through reconfigurable execution sequences.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10805269B2Web application firewall
Publication Date: 2020.10.13 ROYAL BANK OF CANADA
  • US10805269B2 patent drawing
  • US10805269B2 patent drawing
  • US10805269B2 patent drawing

AI summary

Embodiments described herein provide an application programming interface and framework for a web application firewall single policy model. The framework can layer on top of a firewall platform that provides web application specific widgets that may be toggled and configured to enable or disable certain firewall actions on a per application basis. The framework includes a security stack that defines the order for the widgets. The security stack can provide the ability for a single policy model to be used for the firewall and allows for per application customizations.