×

Predicting firewall rule ranking value

  • US 10,645,063 B2
  • Filed: 11/30/2017
  • Issued: 05/05/2020
  • Est. Priority Date: 06/26/2015
  • Status: Active Grant
First Claim
Patent Images

1. A device, comprising:

  • a memory; and

    one or more processors to;

    receive an input indicating a desired accuracy of predictions made using a model;

    determine a size of a training set based on the desired accuracy indicated by the input;

    train the model based on the size of the training set, match counts of match conditions corresponding to a plurality of firewall rules, and performing an analysis of the match counts, of the match conditions corresponding to the plurality of firewall rules, and ranking values corresponding to the plurality of firewall rules;

    receive an unimplemented firewall rule comprising one or more first match condition values;

    identify match counts of the one or more first match condition values based on identifying one or more second match condition values, corresponding to the plurality of firewall rules, that match the one or more first match condition values;

    predict, based on the match counts of the one or more first match condition values, a ranking value corresponding to the unimplemented firewall rule using the model;

    perform an action on a packet, with regard to the unimplemented firewall rule, based on the predicted ranking value;

    determine an actual ranking value for the unimplemented firewall rule;

    perform a comparison of the predicted ranking value and the actual ranking value;

    update the model based on the comparison; and

    replace the predicted ranking value with the actual ranking value after a particular quantity of packets have been received by the device or after a particular period of time has expired.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×