IP Library Granted Patent US 8,468,113
Granted Patent B2
US 8,468,113 · App. 12/885,929 · Granted Jun 18, 2013

Method and system for management of security rule set

Inventors: Reuven Harrison (Tel Aviv, IL); Amir Cogan (Herzliya, IL); Tomer Barkan (Alfei Menashe, IL)
Assignee: Tufin Software Technologies Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,468,113
App. No.
12/885,929
Granted
Jun 18, 2013
Kind
B2
Abstract

There are provided a method of automated managing two or more security rule-sets and a system thereof. The method comprises: obtaining data characterizing a first rule-set and a second rule-set; automated recognizing all possible combinations of values in the first and the second rule-sets; automated verifying each combination of values in the second rule-set against the first rule-set; calculating one or more values characterizing the differences in allowable and rejectable traffic in the first rule-set and the second rule-set; automated comparing the calculated values and/or derivatives thereof with a predefined threshold; and automated classifying the relationship between the first rule-set and the second rule-set in accordance with comparison results. The method may further comprise obtaining a connectivity request; automated verifying each combination of values in the connectivity request against the first rule-set and the second rule-set; and automated classifying the second rule-set with regard to the connectivity request, wherein the second rule-set comprises extra allowable traffic resulting from amending the first rule set.

Claims (92)

1. A method of automated managing a security rule-set, the method comprising:

a. obtaining data characterizing a connectivity request;

b. automated recognizing all possible combinations of values in the connectivity request;

c. automated verifying each combination of values in the connectivity request against a first rule-set;

d. calculating one or more values characterizing relative amount of satisfied and dissatisfied combinations in the request;

e. automated comparing the calculated values or derivatives thereof with a predefined threshold; and

f. automated classifying the connectivity request in accordance with comparison results.

2. The method of claim 1 further comprising:

a. amending the first rule-set, thus giving rise to a second rule set comprising extra allowed traffic resulting from the amended;

b. automated verifying each combination of values in the connectivity request against the second rule-set;

c. calculating one or more values selected from a group comprising values characterizing relative amount of extra allowed traffic and values characterizing relative amount of dissatisfied traffic in the connectivity request;

d. automated comparing the calculated values or derivatives thereof with a predefined threshold; and

e. automated classifying the second rule-set in accordance with comparison results.

3. The method of claim 2 wherein at least one value characterizing relative amount of extra allowed traffic is selected from a group comprising:

a. values characterizing a relation between allowed traffic in the second rule-set and traffic allowed in the first rule-set;

b. values characterizing a relation between entire added traffic and traffic which needs to be added in accordance with the connectivity request; and

c. values characterizing a relation between allowed traffic that has not been requested and traffic allowed in the first rule-set.

4. The method of claim 2 wherein at least one value characterizing relative amount of dissatisfied requested traffic is selected from a group comprising:

a. values characterizing a relation between requested traffic dissatisfied resulting from amendment and requested traffic satisfied resulting from the amendment;

b. values characterizing a relation between requested traffic dissatisfied resulting from the amendment and entire requested traffic; and

c. values characterizing a relation between requested traffic dissatisfied resulting from the amendment and requested traffic dissatisfied before the amendment.

5. The method of claim 1 further comprising generating a verification report.

6. The method of claim 1 wherein the verification is provided with regard to one or more rules within the first rule-set.

7. The method of claim 2 comprising verifying one or more certain rules in the second rule-set against the connectivity request, thereby enabling considering possible side effects related to amending said certain rules.

8. A computer program embodied on a non-transitory computer readable medium comprising computer program code means for performing all the steps of claim 1 when said program is run on a computer.

9. A system capable of automated managing a security rule-set, the system comprising:

a. an interface operable to obtain data characterizing a connectivity request;

b. means for automated recognizing all possible combinations of values in the connectivity request;

c. means for automated verifying each combination of values in the connectivity request against a first rule-set;

d. means for automated calculating one or more values characterizing relative amount of satisfied and dissatisfied combinations in the request;

e. means for automated comparing the calculated values or derivatives thereof with a predefined threshold; and

f. means for automated classifying the connectivity request in accordance with comparison results.

10. The system of claim 9 further comprising:

a. means for obtaining a second rule-set comprising extra allowed traffic resulting from the amending the first rule-set;

b. means for automated verifying each combination of values in the connectivity request against the second rule-set;

c. means for automated calculating one or more values selected from a group comprising values characterizing relative amount of extra allowed traffic and values characterizing relative amount of dissatisfied traffic in the connectivity request;

d. means for automated comparing the calculated values or derivatives thereof with a predefined threshold; and

e. means for automated classifying the second rule-set in accordance with comparison results.

11. The system of claim 10 wherein at least one value characterizing relative amount of extra allowed traffic is selected from a group comprising:

a. value characterizing a relation between allowed traffic in the second rule-set and traffic allowed in the first rule-set;

b. value characterizing a relation between entire added traffic and traffic which needs to be added in accordance with the connectivity request; and

c. value characterizing a relation between allowed traffic that has not been requested and traffic allowed in the first rule-set.

12. The system of claim 10 wherein at least one value characterizing relative amount of dissatisfied requested traffic is selected from a group comprising:

a. value characterizing a relation between requested traffic dissatisfied resulting from amendment and requested traffic satisfied resulting from the amendment;

b. value characterizing a relation between requested traffic dissatisfied resulting from the amendment and entire requested traffic; and

c. value characterizing a relation between requested traffic dissatisfied resulting from the amendment and requested traffic dissatisfied before the amendment.

13. The system of claim 9 further comprising generating a verification report.

14. A method of automated managing two or more security rule-sets, the method comprising:

a. obtaining data characterizing a first rule-set and a second rule-set;

b. automated recognizing all possible combinations of values in the first and the second rule-sets;

c. automated verifying each combination of values in the second rule-set against the first rule-set;

d. calculating one or more values characterizing the differences in allowable and rejectable traffic in the first rule-set and the second rule-set;

e. automated comparing the calculated values or derivatives thereof with a predefined threshold; and

f. automated classifying the relationship between the first rule-set and the second rule-set in accordance with comparison results.

15. A computer program embodied on a non-transitory computer readable medium comprising computer program code means for performing all the steps of claim 14 when said program is run on a computer.

16. The method of claim 14 wherein the second rule-set comprises extra allowable traffic resulting from amending the first rule set, the method further comprising:

a. obtaining a connectivity request;

b. automated recognizing all possible combinations of values in the connectivity request;

c. automated verifying each combination of values in the connectivity request against the first rule-set and the second rule-set;

d. calculating one or more values selected from a group comprising values characterizing relative amount of extra allowed traffic and values characterizing relative amount of dissatisfied traffic in the connectivity request;

e. automated comparing the calculated values or derivatives thereof with a predefined threshold; and

f. automated classifying, in accordance with comparison results, the second rule-set with regard to the connectivity request.

17. The method of claim 16 wherein at least one value characterizing relative amount of extra allowed traffic is selected from a group comprising:

a. value characterizing a relation between allowed traffic in the second rule-set and traffic allowed in the first rule-set;

b. value characterizing a relation between entire added traffic and traffic which needs to be added in accordance with the connectivity request; and

c. value characterizing a relation between allowed traffic that has not been requested and traffic allowed in the first rule-set.

18. The method of claim 16 wherein at least one value characterizing relative amount of dissatisfied requested traffic is selected from a group comprising:

a. value characterizing a relation between requested traffic dissatisfied resulting from amendment and requested traffic satisfied resulting from the amendment;

b. value characterizing a relation between requested traffic dissatisfied resulting from the amendment and entire requested traffic; and

c. value characterizing a relation between requested traffic dissatisfied resulting from the amendment and requested traffic dissatisfied before the amendment.

19. A system capable of automated managing a security rule-set, the system comprising:

a. means for obtaining data characterizing a first rule-set and a second rule-set;

b. means for automated recognizing all possible combinations of values in the first and the second rule-sets;

c. means for automated verifying each combination of values in the second rule-set against the first rule-set;

d. means for calculating one or more values characterizing the differences in allowable and rejectable traffic in the first rule-set and the second rule-set;

e. means for automated comparing the calculated values or derivatives thereof with a predefined threshold; and

f. means for automated classifying the relationship between the first rule-set and the second rule-set in accordance with comparison results.

20. The system of claim 19 wherein the second rule-set comprises extra allowable traffic resulting from amending the first rule set, the system further comprising:

a. means for obtaining a connectivity request;

b. means for automated recognizing all possible combinations of values in the connectivity request;

c. means for automated verifying each combination of values in the connectivity request against the first rule-set and the second rule-set;

d. means for calculating one or more values selected from a group comprising values characterizing relative amount of extra allowed traffic and values characterizing relative amount of dissatisfied traffic in the connectivity request;

e. means for automated comparing the calculated values or derivatives thereof with a predefined threshold; and

f. means for automated classifying, in accordance with comparison results, the second rule-set with regard to the connectivity request.

21. The system of claim 20 wherein at least one value characterizing relative amount of extra allowed traffic is selected from a group comprising:

a. value characterizing a relation between allowed traffic in the second rule-set and traffic allowed in the first rule-set;

b. value characterizing a relation between entire added traffic and traffic which needs to be added in accordance with the connectivity request; and

c. value characterizing a relation between allowed traffic that has not been requested and traffic allowed in the first rule-set.

22. The system of claim 20 wherein at least one value characterizing relative amount of dissatisfied requested traffic is selected from a group comprising:

a. value characterizing a relation between requested traffic dissatisfied resulting from amendment and requested traffic satisfied resulting from the amendment;

b. value characterizing a relation between requested traffic dissatisfied resulting from the amendment and entire requested traffic; and

c. value characterizing a relation between requested traffic dissatisfied resulting from the amendment and requested traffic dissatisfied before the amendment.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 25, 2022
From: TUFIN SOFTWARE TECHNOLOGIES LTD.
To: TCG SENIOR FUNDING, L.L.C., AS COLLATERAL AGENT
Reel/Frame 061326/0981 →
TERMINATION OF LIENS RECORDED AT REEL/FRAME 036275/0190 AND 041470/0868 Recorded Jul 5, 2022
From: SILICON VALLEY BANK
To: TUFIN SOFTWARE TECHNOLOGIES LTD.
Reel/Frame 060574/0355 →
SECURITY AGREEMENT Recorded Aug 4, 2015
From: TUFIN SOFTWARE TECHNOLOGIES LTD
To: SILICON VALLEY BANK
Reel/Frame 036275/0190 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2010
From: HARRISON, REUVEN; COGAN, AMIR; BARKAN, TOMER
To: TUFIN SOFTWARE TECHNOLOGIES LTD.
Reel/Frame 025310/0730 →
Continuity (3)
Continuation In Part 12781352 · May 17, 2010
Provisional Application 61179089 · May 18, 2009
Related Publication 20110060713A1 · Mar 10, 2011