Web Application Firewall Policy Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large enterprises face challenges in implementing effective web application firewall policies due to the need for customized security measures for each web application, leading to watered-down policies that offer inadequate protection and require time-consuming manual programming by skilled developers.
Innovation Solution
A firewall system with a processor that configures widgets for web applications, featuring a security stack with an order of execution for widgets to enable or disable security actions on a per-application basis, including state control and security widgets for behavior analysis, signature detection, and virtual patching, allowing for customizable and efficient security policies without requiring extensive programming.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single firewall policy is applied to all web applications, then policy implementation is simplified, but security protection becomes inadequate due to watered-down rules
Solution Approach 1:
The patent segments the firewall policy into multiple widgets that can be independently configured and applied to different web applications. Each widget represents a discrete security rule that can be selectively enabled or disabled, allowing customized security policies per application while maintaining centralized management through the security stack.
2Reliability
If customized firewall policies are created for each web application, then security protection is enhanced, but policy configuration becomes complex and time-consuming
Solution Approach 1:
The patent implements self-service capabilities through automated widget generation that creates firewall rules based on application fingerprints and security requirements. The system automatically configures widgets for each web application without requiring manual programming, reducing complexity while maintaining customized security policies.
Solution Approach 2:
The patent uses parameter changes to dynamically adjust firewall policies based on application-specific parameters such as traffic patterns, security requirements, and application fingerprints. The security stack evaluates these parameters and automatically configures appropriate widgets, enabling customized policies without manual intervention.
3Adaptability or versatility
If manual programming is used to create firewall rules, then policy customization is achieved, but development time and skill requirements increase
Solution Approach 1:
The system performs self-service by automatically generating firewall widgets through application fingerprinting and security requirement analysis. The security stack autonomously creates and configures widgets without requiring skilled programmers, eliminating manual coding while maintaining policy adaptability to each application's specific needs.
Solution Approach 2:
The patent applies preliminary action by pre-configuring security widgets based on application fingerprints and security templates before deployment. The system prepares customized security policies in advance through automated analysis, eliminating the need for manual programming during implementation and reducing both time and skill requirements.
4Productivity
If security widgets are executed in a fixed order, then processing efficiency is improved, but flexibility in security control is reduced
Solution Approach 1:
The patent implements dynamics by making the widget execution order configurable and adaptable to different security scenarios. The security stack allows widgets to be arranged in different sequences based on application requirements and security priorities, providing both efficient processing through optimized ordering and flexibility through reconfigurable execution sequences.
Data Source
AI summary
Embodiments described herein provide an application programming interface and framework for a web application firewall single policy model. The framework can layer on top of a firewall platform that provides web application specific widgets that may be toggled and configured to enable or disable certain firewall actions on a per application basis. The framework includes a security stack that defines the order for the widgets. The security stack can provide the ability for a single policy model to be used for the firewall and allows for per application customizations.


