IP Library Granted Patent US 7,406,534
Granted Patent B2
US 7,406,534 · App. 10/321,851 · Granted Jul 29, 2008

Firewall configuration validation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,406,534
App. No.
10/321,851
Granted
Jul 29, 2008
Kind
B2
Abstract

The invention relates to processing configuration of a network node, such as for example a firewall, and for sharing the configuration management between several administrators. The configuration comprises a processing rule base, which contains rules to be used in the network node for filtering data packets, the rules comprising one or more identification values for identifying a data packet and an action. The configuration of the network node is validated by determining, whether the processing rule base fulfils requirements defined in a validation rule base. The use of validation rule base enables verifying that processing rule bases managed by different administrators fulfil some set requirements. Additionally, the invention accounts for detecting human errors in configurations.

Claims (40)

1. A method of managing configuration of a network node, the configuration comprising a processing rule base, which contains rules to be used in the network node for filtering data packets, the rules comprising one or more identification values for identifying a data packet and an action, said method comprising

validating the configuration of the network node by evaluating each rule in a new or modified processing rule base against requirement defined in a validation rule base, and accepting the processing rule base for the network node only if the requirements are fulfilled, the validation rule base comprising at least one validation rule having one or more identification values and at least one associated required action.

2. A method according to claim 1 , wherein the evaluating comprises:

finding the at least one action defined in the processing rule base for at least one identification value of a validation rule,

passing the validation rule, if said at least one action conforms to the required at least one action in said validation rule, and failing the validation rule, if said at least one action does not conform to the required at least one action in said validation rule, and

passing the validation, if all validation rules are passed.

3. A method according to claim 1 , comprising validating the configuration as a response to a predefined action.

4. A method according to claim 3 , wherein the said predefined action is a command by a user to perform the validation, starting up of the network node, uploading a new or modified configuration to the network node or saving a configuration.

5. A method according to claim 1 , comprising rejecting the configuration, if the requirements defined in the validation rule base are not fulfilled.

6. A method according to claim 1 , comprising generating an error message, if the requirements defined in the validation rule base are not fulfilled.

7. A method according to any one of claims 2 to 6 , comprising outputting a rule of the processing rule base, which does not conform to a validation rule.

8. A method according to claim 1 , wherein several administrators are allowed to modify or create a processing rule base and in that a super user is allowed to modify or create a validation rule base.

9. A method according to claim 1 , wherein an administrator is allowed to modify or create a processing rule base and a validation rule base.

10. A method according to claim 1 , comprising

generating a processing rule base model corresponding to said processing rule base and indicating the effective processing rule base rules, and

using the processing rule base model in the evaluation of each rule in the new or modified processing rule base.

11. A method according to claim 1 , comprising

generating a validation rule base model corresponding to said validation rule base and indicating the effective validation rule base rules, and

using the validation rule base model in the evaluation of each rule in the new or modified processing rule base.

12. A method according to any one of claims 10 and 11 , wherein generating a processing or a validation rule base model comprises

arranging rules of the rule base into groups of rules, the rules in a group having a common identification value while keeping a track of the order of the rules in the rule base.

13. A method according to claim 12 , wherein one group corresponds at least one service or port number.

14. A method according to claim 10 or 11 , wherein generating a processing or a validation rule base model comprises:

if there exist overlapping identification value combinations in two or more rules of the rule base, maintaining the first one of the two or more rules in the order of the rules unchanged and removing such overlapping identification values from others of the two or more rules for determining the effective identification values in each rule.

15. A method according to claim 10 or 11 , wherein generating a processing or a validation rule base model comprises

combining the effects of NAT (Network Address Translation) rules into said processing rule base model by changing addresses and/or port numbers of rules in said processing rule base to real addresses and/or port numbers.

16. A method according to claim 1 , wherein said processing rule base is an access rule base or a routing table.

17. A method according to claim 1 , wherein said network node is a security gateway, a firewall, a router or a VPN (Virtual Private Network) gateway.

18. A computer-readable medium, containing a computer software which, when executed in a computer device, causes the computer device to provide a routine for managing configuration of a network node, the configuration including a processing rule base, which contains rules to be used in the network node for filtering data packets, the rules including one or more identification values for identifying a data packet and an action, said routine comprising

validating the configuration of the network node by evaluating each rule in a new or modified the processing rule base against requirements defined in a validation rule base, and accepting the processing rule base for the network node only if the requirements are fulfilled, the validation rule base comprising at least one validation rule having one or more identification values and at least one associated required action.

19. A computer-readable medium according to claim 18 , wherein the evaluating comprises:

finding the action(s) defined in the processing rule base for identification value(s) of a validation rule,

passing the validation rule, if said at least one action conforms to the required at least one action in said validation rule, and failing the validation rule, if said at least one action does not conform to the required at least one action in said validation rule, and

passing the validation, if all validation rules are passed.

20. An arrangement for managing configuration of a network node, the configuration including a processing rule base, which contains rules to be used in the network node for filtering data packets, the rules including one or more identification values for identifying a data packet and an action, the arrangement comprising:

a validation mechanism for validating the configuration of the network node by evaluating each rule in a new or modified the processing rule base against requirements defined in a validation rule base, and accepting the processing rule base for the network node only if the requirements are fulfilled, the validation rule base comprising at least one validation rule having one or more identification values and at least one associated required action.

21. An arrangement according to claim 20 , wherein the validation mechanism is arranged to:

find the at least one action defined in the processing rule base for at least one identification value of a validation rule,

pass the validation rule, if said at least one action conforms to the required at least one action in said validation rule, and to fail the validation rule, if said at least one action does not conform to the required at least one action in said validation rule, and

pass the validation, if all validation rules are passed.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FINLAND OY
To: FORCEPOINT LLC
Reel/Frame 043156/0547 →
CHANGE OF NAME Recorded Apr 15, 2016
From: WEBSENSE FINLAND OY
To: FORCEPOINT FINLAND OY
Reel/Frame 038447/0441 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2016
From: STONESOFT OY DBA STONESOFT CORPORATION
To: WEBSENSE FINLAND OY
Reel/Frame 037828/0385 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2003
From: SYVANNE, TUOMO; LILIUS, EINO
To: STONESOFT CORPORATION
Reel/Frame 013822/0005 →