Web Application Firewall Rule Set Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing web application firewalls face challenges in efficiently updating rule sets to prevent legitimate requests and responses from being blocked, leading to high resource consumption and service disruptions due to manual and time-consuming maintenance processes.

Innovation Solution

A method that automatically optimizes rule sets by enabling or disabling rules based on client reputation and fallibility scores, reducing the number of legitimate requests and responses blocked, using a web application firewall subsystem with a response engine, reputation engine, and fallibility engine to generate and maintain application-specific rule sets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual rule set updates are performed periodically, then security protection is maintained, but time consumption and resource requirements increase significantly

Engineering Contradiction:
Improvesecurity protectionVSAvoidtime consumption for updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically monitors filtering operations, computes quality scores for rules, and disables ineffective rules without human intervention. The fallibility engine continuously evaluates rule performance and self-adjusts the rule set, eliminating the need for manual updates while maintaining security protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback mechanism where filtering operation results are continuously monitored and fed back to the fallibility engine. Quality scores are computed based on this feedback, and rules are automatically adjusted according to their performance metrics, creating a closed-loop system that adapts over time.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual rule set inspection and modification is performed, then erroneous blocking is reduced, but productivity decreases due to tedious manual processes

Engineering Contradiction:
Improvereduction of erroneous blockingVSAvoidrule set update efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical processes of inspection and modification with automated computational systems. The fallibility engine uses algorithms to automatically identify and disable erroneous rules, substituting human analysts with machine-based automated rule evaluation and adjustment mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If comprehensive negative assertion rule sets are implemented, then malicious requests are blocked effectively, but legitimate requests are erroneously blocked

Engineering Contradiction:
Improvemalicious request blockingVSAvoidlegitimate request delivery
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system dynamically adjusts rule effectiveness based on continuous monitoring of filtering operations. Rules are not statically applied but are continuously evaluated through quality scores and fallibility metrics, allowing the system to adapt rule application in real-time based on observed performance and changing traffic patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of rule quality from a static binary state to a dynamic quality score that evolves based on filtering operation results. This parameter change enables the system to differentiate between effective and ineffective rules, adjusting rule application based on computed quality metrics rather than fixed configurations.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If rule sets are updated frequently to adapt to application changes, then protection accuracy improves, but resource consumption and service disruptions increase

Engineering Contradiction:
Improveprotection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system performs periodic evaluation of rule quality through automated monitoring of filtering operations. Instead of continuous manual updates, the fallibility engine periodically computes quality scores and disables rules that fall below effectiveness thresholds, implementing rhythmic automated adjustments that balance accuracy with resource conservation.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10063519B1Automatically optimizing web application firewall rule sets
Publication Date: 2018.08.28 VERISIGN INC
  • US10063519B1 patent drawing
  • US10063519B1 patent drawing
  • US10063519B1 patent drawing

AI summary

In one embodiment, a rule optimization application optimizes a rule set that a firewall applies to protect web applications from on-line attacks. The rule optimization application identifies a completed filtering operation that is associated with applying a rule to a request to access a web application received from a client. The rule optimization application then estimates a quality score for the rule based on the completed filtering operation and a reputation value for the client that indicates a likelihood that the client is legitimate. Subsequently, the rule optimization application determines that the quality score does not satisfy a predetermined quality criterion and disables the rule in the rule set to generate a updated, optimized rule set for the web application. Advantageously, the quality criterion may configure the rule optimization application to automatically update the rule set to reduce the number of legitimate requests that are blocked by the rule set.