The world is witnessing a new peak of technological evolution. At Cisco, we are at the heart of this innovation, and nothing makes us prouder than watching our own people take these values into their own hands.
Earlier this year, a team of talented engineers in Lisbon collaborated to solve a long-standing industry challenge: manual firewall management. Their work resulted in a new patent that enables a smooth transition from manual bottlenecks to automated security, delivering a 95% impact in time savings.
Ahmed Abdel Mawgoud, Hugo Amaro, Nikolai Gubanov and Vitor Manuel Carujo Leitao are the faces beyond this remarkable milestone. The Cisco Portugal Blog team was able to meet them to understand more about their innovation.
1. Prior Art Search: Why are we doing this?
Every great innovation starts with a question. For our team in Lisbon, that question was simple: Why are we still managing complex firewall rules manually in an era of automated networks?
In today’s hyper-dynamic network environments, manual firewall management is more than just a task; it’s a liability. Security teams often face significant risks, including misconfigurations, policy conflicts, and omissions that create critical vulnerabilities. When security relies on traditional hands-on configuration for hundreds of thousands of entries, the margin for human error increases, as does the time required to respond to emerging threats. Our team identified this “either-or” mentality—prioritizing either network performance or stringent security—as the primary obstacle to a truly scalable defense.
2. Drafting the Patent: The “Secret Ingredient”
The secret ingredient behind our new patent is “context.”
“Without visibility into how applications communicate, administrators often create overly permissive rules to avoid breaking services, which inadvertently expands the attack surface.”
The team’s innovation involves integrating Cisco Secure Firewalls with the telemetry of Cisco Secure Network Analytics (formerly Stealthwatch). By mapping real-world traffic flows, they moved beyond static rule-making into granular interaction. They built a communication flow matrix, which is generalized to create precise, efficient firewall rules. This technology doesn’t just capture the network; it understands it.
3. Filing the Application: Real-World Validation
To move from a concept to a patent, the team needed to prove the efficacy of their approach. The trigger came from a real-life project they were handling within EMEA.
“We observed that manual configuration was a major bottleneck during the process of firewall rules optimization with hundreds of thousands of entries,” the team noted.
By applying their methodology to this complex, live environment, they were able to demonstrate that their solution was not just a theoretical improvement, but a scalable, enterprise-grade necessity. This phase of validation was the crucible that turned a creative idea into a robust, patentable security standard.
4. Examination: Data-Driven Refinement
During the development process, the team refined their algorithm to automatically generate, validate, and refine firewall rules. By analyzing traffic flows, the system captures specific protocols, ports, traffic amounts, and zone-to-zone behaviors—details that are often invisible to standard firewalls.
This data-driven approach ensures that rules are based on actual, legitimate traffic patterns. The system can distinguish between authorized connections and potential threats, enabling the automated generation of highly accurate, context-aware firewall policies. This process of continuous refinement is what ensures the security posture remains agile and accurate.
5. Allowance and Grant: The Impact
The impact of this innovation is measurable: a 95% reduction in configuration time. This is a paradigm shift for administrators and analysts. By automating the repetitive aspects of rule creation, teams can reclaim significant time to focus on high-value strategic initiatives, such as proactive threat hunting, strategic incident response, and in-depth security analysis.
Conclusion
Ultimately, this patent empowers customers to stay ahead of cyberthreats, ensuring their security infrastructure is optimized, resilient, and aligned with best practices, regardless of how complex their network environment becomes.
“This automation fundamentally shifts the security posture from reactive to proactive. By continuously monitoring traffic and automatically refining rules, the system maintains an agile defense that adapts to evolving threats in real-time. It minimizes the attack surface by enforcing restrictive rules based on actual network behavior, ensuring that only authorized traffic is permitted.”
A big thank you, and well-deserved congratulations to Ahmed Abdel Mawgoud, Hugo Amaro, Nikolai Gubanov and Vitor Manuel Carujo Leitao, the official innovators behind this patent, who helped us shape this article.