Networking and Security Split Architecture
The networking and security split architecture addresses the challenge of managing high-bandwidth environments by separating security and networking functions, enhancing performance and cost-efficiency through flexible deployment and resource aggregation.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- PALO ALTO NETWORKS INC
- Filing Date
- 2022-12-06
- Publication Date
- 2026-05-15
AI Technical Summary
Existing security solutions struggle to efficiently manage high-bandwidth network environments, particularly in cloud-based settings, due to the technical challenges of achieving elasticity and leveraging third-party or cloud provider services for improved service level performance and availability, especially in environments with increasing bandwidth requirements.
A networking and security split architecture is implemented, dividing security entities into a networking function layer and a security function layer, where the networking layer handles tasks like IPSec termination and routing, while the security layer performs security tasks such as Layer 7 content inspection, with an offload interface between the two layers.
This approach enhances performance by reducing the need for CPU-intensive security tasks in the networking layer, allowing for better aggregation of networking resources and flexible deployment of security offload layers, resulting in improved throughput and cost savings without compromising security integrity.
Smart Images

Figure 0007860235000002 
Figure 0007860235000003 
Figure 0007860235000004
Abstract
Description
Background Art
[0001] A firewall generally protects a network from unauthorized access while allowing authorized communications to pass through the firewall. A firewall is typically a device or a set of devices, such as a computer, or software executed on a device, that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, a smartphone, or other types of network - communicable devices). A firewall can also be integrated into or executed as software on a computer server, a gateway, a network / routing device (e.g., a network router), or a data appliance (e.g., a security device or other types of dedicated devices).
[0002] A firewall typically rejects or permits network transmissions based on a set of rules. These sets of rules are often called policies. For example, a firewall can filter inbound traffic by applying a set of rules or policies. A firewall can also filter outbound traffic by applying a set of rules or policies. A firewall can also perform basic routing functions.
Brief Description of the Drawings
[0003] Various embodiments of the present invention are disclosed in the following detailed description and the accompanying drawings. [Figure 1] FIG. 1 is a functional diagram related to a system architecture for providing a networking and security split architecture according to some embodiments. [Figure 2]Figure 2 is another functional diagram relating to a system architecture for providing a networking and security split architecture according to several embodiments. [Figure 3] Figure 3 is another functional diagram relating to a system architecture for providing a networking and security split architecture according to several embodiments. [Figure 4A] Figure 4A shows one embodiment of a data appliance. [Figure 4B] Figure 4B is a functional diagram of a logical component according to one embodiment of a data appliance. [Figure 5] Figure 5 is a flowchart showing the process for providing a networking and security split architecture according to several embodiments. [Figure 6] Figure 6 is another flowchart illustrating the process for providing a networking and security split architecture according to several embodiments. [Figure 7] Figure 7 shows one example of the performance improvements provided by a networking and security split architecture according to several embodiments. [Modes for carrying out the invention]
[0004] The present invention can be implemented in numerous ways, including a processor, such as a process, apparatus, system, composition, computer program product embodied on a computer-readable storage medium, and / or instructions stored in memory coupled to a processor, and / or a processor configured to execute instructions provided by memory. These implementations, or any other forms the present invention may take, may be referred to as techniques. Generally, the order of the steps of the disclosed process may be modified within the scope of the invention. Unless otherwise specified, components such as processors or memory described as configured to perform a task may be implemented as general-purpose components temporarily configured to perform a task at a given time, or as predetermined components manufactured to perform a task. As used herein, the term “processor” refers to one or more devices, circuits, and / or processing cores configured to process data, such as computer program instructions.
[0005] A detailed description of one or more embodiments of the present invention, along with accompanying drawings illustrating the principles of the present invention, is provided below. While the present invention is described in relation to such embodiments, it is not limited to any embodiment. The scope of the present invention is limited only by the claims, and the present invention encompasses numerous alternatives, modifications, and equivalents. In order to provide a complete understanding of the present invention, numerous specific details are described in the following description. These details are provided for illustrative purposes, and the present invention may be carried out in accordance with the claims without some or all of these specific details. For clarity, technical materials known in the art related to the present invention are not described in detail so as not to unnecessarily obscure the present invention.
[0006] Advanced or next-generation firewalls
[0007] Malware is a term commonly used to refer to malicious software (including, for example, various adversarial, intrusive, and / or otherwise unwanted software). Malware can take the form of code, scripts, active content, and / or other software. Exemplary uses of malware include disrupting computer and / or network operation, stealing confidential information (such as identity, financial, and / or intellectual property-related information), and / or gaining access to private / dedicated computer systems and / or computer networks. Unfortunately, as techniques to help detect and mitigate malware are developed, nefarious authors find ways to circumvent such efforts. Therefore, the need for improvement in techniques for identifying and mitigating malware remains.
[0008] A firewall generally allows authorized communications to pass through while protecting the network from unauthorized access. Typically, a firewall is a device, a set of devices, or software running on a device that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of network-enabled device). Firewalls can also be integrated into or run as software applications on various types of devices or security devices, such as computer servers, gateways, network / routing devices (e.g., network routers), or data appliances (e.g., security equipment, or other types of special-purpose devices, and in some implementations, the specified operation can be implemented within dedicated hardware such as ASICs or FPGAs).
[0009] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often called policies (e.g., network policies or network security policies). For example, a firewall can filter inbound traffic by applying a set of rules or policies to prevent unwanted external traffic from reaching the protected device. Firewalls can also filter outbound traffic by applying a set of rules or policies (e.g., allow, block, monitor, notify, log, and / or other actions that may be specified in firewall rules or firewall policies, which can be triggered based on various criteria, as described herein). Firewalls can also filter local network (e.g., intranet) traffic by similarly applying a set of rules or policies.
[0010] Security devices (e.g., security equipment, security gateways, security services, and / or other security devices) can perform a variety of security operations (e.g., firewalls, anti-malware, intrusion prevention / detection, proxies, and / or other security functions), network functions (e.g., routing, quality of service (QoS), workload balancing of network-related resources, and / or other networking functions), and / or other security and / or networking-related operations. For example, routing can be performed based on source information (e.g., IP address and port), destination information (e.g., IP address and port), and protocol information (e.g., Layer 3 IP-based routing).
[0011] Basic packet filtering firewalls filter network communication traffic by inspecting individual packets transmitted across the network (e.g., packet filtering firewalls or first-generation firewalls, which are stateless packet filtering firewalls). Stateless packet filtering firewalls typically inspect the individual packets themselves and then apply rules based on the inspected packets (e.g., using a combination of source and destination address information, protocol information, and port number).
[0012] An application firewall can also perform application layer filtering (for example, using an application layer filtering firewall or a second-generation firewall that operates at the application level of the TCP / IP stack). An application layer filtering firewall or application firewall can generally identify a given application and protocol (e.g., web browsing using Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfers using File Transfer Protocol (FTP), and various other types of applications and protocols such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, an application firewall can block unauthorized protocols attempting to communicate through standard ports (for example, unauthorized / unauthorized policy protocols attempting to sneak through by using non-standard ports for that protocol can generally be identified using an application firewall).
[0013] A stateful firewall can also perform stateful-based packet inspection, where each packet is examined within the context of a set of packets associated with its network transmission packet flow (e.g., a stateful firewall or third-generation firewall). This firewall technique is commonly called stateful packet inspection because it maintains a record of all connections passing through the firewall and can determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, the state of a connection can itself be one of the criteria that trigger rules in a policy.
[0014] Advanced or next-generation firewalls, as described above, can perform stateless and stateful packet filtering and application layer filtering. Next-generation firewalls can also perform additional firewall techniques. For example, a given new firewall, sometimes referred to as an advanced or next-generation firewall, can also identify users and content. In particular, a given next-generation firewall extends the list of applications these firewalls can automatically identify to thousands. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks' PA Series firewalls).
[0015] For example, Palo Alto Networks' next-generation firewalls use various identification technologies to enable enterprises to identify and control applications, users, and content—not just ports, IP addresses, and packets. These identification technologies include Application ID (App-ID) for precise application identification, User ID (User-ID) for user identification (e.g., a user or user group), and Content ID (Content-ID) for real-time content scanning (e.g., controlling web surfing and restricting data and file transfers). These identification technologies allow enterprises to securely enable application use using business-relevant concepts, rather than following the traditional approach provided by conventional port-blocking firewalls. Furthermore, purpose-specific hardware for next-generation firewalls generally offers higher performance levels for application inspection than software running on general-purpose hardware (for example, Palo Alto Networks' security devices, which utilize dedicated, function-specific processing tightly integrated with a single-path software engine to minimize latency while maximizing network throughput).
[0016] Advanced or next-generation firewalls can also be implemented using virtualized firewalls. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (Palo Alto Networks firewalls are, for example, used with VMware(R) ESXi). TM and NSX TM Citrix(R) Netscaler SDX TMIt supports a variety of commercial virtualization environments, including KVM / OpenStack (CentOS / RHEL, Ubuntu(R)), and Amazon Web Services (AWS). For example, virtualization firewalls can support similar or identical next-generation firewalls and advanced threat prevention features available in physical form factor devices, enabling enterprises to ensure that applications can flow safely into and across their private, public, and hybrid cloud computing environments. Automation features such as VM monitoring, dynamic address groups, and REST-based APIs allow enterprises to dynamically monitor VM changes and reflect that context in security policies, thereby eliminating potential policy lag that can occur when VMs change.
[0017] Technical challenges of security solutions in network environments with increasing bandwidth.
[0018] Security service providers offer a variety of commercially available security solutions, including various firewalls, VPNs, and other security-related services. For example, some security service providers offer such security solutions to their customers, including various firewalls, VPNs, and other security-related services. However, increasing bandwidth network environments (e.g., enterprise network environments with 100 gigabyte (100G) links) present technical challenges to such security solutions.
[0019] Specifically, what is needed is a new and improved solution for efficiently promoting high throughput for such security solutions. For example, private and public cloud networks are moving towards networks with speeds of 100G or higher (e.g., networks having links of 100G or higher). As a result, providing virtual security solutions is becoming increasingly expensive (e.g., virtual security solutions for firewalls commercially available from Palo Alto Networks at 100G or higher speeds, which are provided using various commercial virtualization environments including, for example, VMware(R) ESXi TM and NSX TM , Citrix(R) Netscaler SDX TM , KVM / OpenStack (Centos / RHEL, Ubuntu(R)), and Amazon Web Services (AWS), or various other commercially available firewall solutions). One example of an existing approach is to attempt offloading using a VM / CN series virtualization environment in user space. However, this approach is expensive in terms of the computing resources utilized for such offloading operations.
[0020] An overview of techniques for providing networking and security split architectures.
[0021] In the current SASE (Security Access Service Edge) environment, there are many technical challenges that we need to overcome. Examples of these technical challenges will be described hereinafter. Networking functions are centered around networking and are associated with external resources that are not inherently elastic, such as public IP addresses and private IP address pools. Also, it is generally technically difficult to achieve true elasticity for security processing capabilities. As another example, it is generally technically difficult to leverage third-party or cloud provider services and functions to achieve better service level performance and availability.
[0022] Therefore, various techniques for providing a networking and security split architecture are disclosed. One example described herein is a new networking and security split architecture that divides security entities into a networking function layer and a security function layer (e.g., a network gateway firewall (NGFW) such as using the PanOS platform, e.g., the Palo Alto Networks VM / CN series virtual firewall platform available from Palo Alto Networks, headquartered in Santa Clara, California, or other commercially available security platforms can be similarly modified using the split networking and security architecture techniques described herein).
[0023] In an exemplary implementation, the networking functionality layer is implemented on the front end to terminate and handle networking tasks such as IPSec termination, routing, and network address translation (NAT). This layer is referred to as the Networking Anchor Layer. The security functionality layer is deployed on the back end to handle security tasks such as Layer 7 content inspection, SSL decryption, and URL filtering. This layer is referred to as the Security Offloading Layer. The interface between these two layers is called the offload interface.
[0024] In this exemplary implementation, once network traffic is received at the networking anchor layer, we can apply IPSec termination, networking lookup, and load balancing to various security offload layer instances. The security offload layer instances then perform security policy lookup, Layer 7 content inspection, and possible SSL decryption, or other security functions. After security processing, the network traffic is forwarded back to the networking anchor layer for routing and possible NAT functions.
[0025] The disclosed networking and security split architectures offer various improvements over existing approaches to security solutions. For example, the networking anchor layer can provide better unit performance because such layers are not required to perform CPU-intensive security tasks. Thus, this layer can aggregate more networking resources, such as public and private IP address pools. This generally reduces the changes and difficulties required to manage these networking resources across instance boundaries (e.g., across virtual firewall instance boundaries).
[0026] As another example, the security offload layer is relatively network-independent (agnostic). Therefore, the security offload layer can be deployed more flexibly without networking or location knowledge.
[0027] In some embodiments, a system, process, and / or computer program product for providing a networking and security split architecture includes receiving flows in a security service (e.g., a cloud-based security service, such as using one public cloud service provider or multiple public cloud service providers), processing flows in the network layer of the security service (e.g., a network anchor instance) to perform one or more networking functions, and offloading flows to the security layer of the security service (e.g., an offload security instance) to perform security enforcement based on policies.
[0028] For example, a flow is determined to be a new flow by a security service, and metadata can be extracted from the flow during processing at the network layer of the security service. The metadata then includes the application identification associated with the flow.
[0029] Flow processing at the network layer may include performing one or more of the following: IPsec termination, routing, network address translation (NAT), and deep packet inspection.
[0030] The security layer may include multiple security instances (e.g., a firewall), and / or the multiple security instances may be implemented to run separate microservices of security functions, including one or more of the following: antivirus, anti-spam, DNS security, intrusion detection / prevention security (IDS / IPS), and data extraction security.
[0031] The network layer may include one or more of the following: a network router, a virtual private network (VPN) gateway, and a load balancer (for example, a load balancer can send the first packet of a session to one security instance in the security layer and subsequent packets of the same session to the same security instance in the security layer).
[0032] After a flow is closed, session statistics associated with the flow may be generated by the security layer.
[0033] The disclosed technologies, which provide networking and security split architectures, can be applied to any deployment for enhanced security solutions. As one example, the disclosed technologies can be applied to high-bandwidth network environments, such as service provider network environments. Specifically, service provider deployments (e.g., AT&T, Verizon, or other commercial service cellular and / or Internet / network service provider deployments) are generally associated with high-bandwidth network environments (e.g., such service providers typically require very high throughput (e.g., 100 Gbps)). Service provider deployments are also generally associated with network environments where the majority of network traffic is typically passthrough traffic (e.g., elephant flow). Thus, a significant proportion of network traffic in a service provider network resides in a smaller number of flows that have the potential to be bypassed for security checks (for example, in one exemplary service provider network, approximately 80% of network traffic can be offloaded, as this represents the proportion of elephant flows passing through this exemplary service provider network). These elephant flows are typically video streams (e.g., video streaming using Netflix, YouTube®, etc.) and / or video conferencing (e.g., video conferencing using Zoom, WebEx, etc.).
[0034] Other exemplary types of network traffic that can benefit from using the disclosed techniques to provide networking and security split architectures include SSH, SSL, and IPSEC-related network traffic, which is encrypted using these or other encrypted network protocols. Assuming a service provider is typically in the middle of the flow between their customers, the service provider generally does not possess the keys necessary to inspect such encrypted network traffic, and thus this encrypted traffic can also be effectively offloaded using the disclosed techniques. Various other types of network traffic can similarly be effectively offloaded using the disclosed techniques.
[0035] Accordingly, various techniques for providing networking and security split architectures are disclosed and further described below.
[0036] Exemplary system embodiment for providing a networking and security split architecture
[0037] Figure 1 is a functional diagram relating to a system architecture for providing a networking and security split architecture according to several embodiments. Referring to Figure 1, a networking and security split architecture solution 102 (for example, implemented as a cloud-based security service in a virtual private cloud (VPC)) is provided. It includes a Networking Anchor Layer 104A (a lightweight version of the disclosed Networking Anchor Layer (e.g., without security processing components) that implements layers for routing, networking termination, underlay tunneling, network address translation (NAT), etc.), an Offloading Interface 106 (e.g., implementing layers for providing a functional interface between the networking layer and the security layer), and a Security Offloading Layer 108 (dynamically allocated security processing instances for implementing layers for security processing such as SSL decryption, deep packet inspection (DPI) for security policy enforcement, etc.). As shown in the figure, the Networking Anchor Layer includes the following exemplary components. Specifically, the router 114, VPN gateway 116, and load balancer 118 (for example, implemented as an adaptive load balancer which performs policy-based forwarding (PBF) and supports forwarding traffic to next-hop groups which can include multiple destinations (offload instances) which can be added or removed dynamically, and similarly uses a group-based load balancing hash algorithm (e.g., session ID / source only / destination only / source-destination / etc.).Furthermore, as illustrated, the security offload layer includes a security instance group (for example, it may include multiple PanOS instances, or another commercially available virtual / container-based security platform layer may be implemented in this layer).
[0038] In this exemplary implementation, the networking anchor layer can provide better unit performance because such layers are not required to perform CPU-intensive security tasks. Thus, this layer can aggregate more networking resources, such as public and private IP address pools. This generally reduces the changes and difficulties required to manage these networking resources across instance boundaries (e.g., across virtual firewall instance boundaries). Furthermore, this exemplary lightweight networking anchor layer (e.g., a pure networking anchor layer) can cover 100% of network traffic using the same forwarding path (e.g., providing the same scaling behavior for all applications while maintaining security integrity). The security offload layer is relatively network-independent. Thus, the security offload layer can be deployed more flexibly without networking or location knowledge.
[0039] Network traffic from Branch Offices 112A and 112B is sent to the networking anchor layer via an IPSec tunnel. The router routes unencrypted traffic to the security offload layer and encrypted traffic to the VPN gateway. The router can also route traffic to and from the Internet 110. A load balancer dynamically load-distributes network traffic across various security instances in the security offload layer (based on Layer 4 information associated with network traffic or sessions, for example), as shown. In this exemplary implementation, IP user mappings are generated at both the networking anchor layer and the security offload layer, and entries generated in one instance can be synchronized to all other instances.
[0040] Figure 2 is another functional diagram relating to a system architecture for providing a networking and security split architecture according to several embodiments. Referring to Figure 2, a networking and security split architecture solution 102B (for example, implemented as a cloud-based security service in a virtual private cloud (VPC)) is similarly provided. It includes a networking anchor layer 104B (for example, implementing layers for routing, networking termination, underlay tunneling, network address translation (NAT), etc.), an offload interface 106 (for example, dynamically allocated security processing instances that implement layers for providing a functional interface between the network layer and the security layer), and a security offload layer 108 (for example, implementing layers for security processing such as SSL decryption, deep packet inspection (DPI) for security policy enforcement, etc.). As illustrated, the networking anchor layer in this exemplary implementation includes the following exemplary components: Specifically, these include a router 114, a VPN gateway 116, and a load balancer 118, as well as a security processing component 120 for performing security processing (e.g., 5% throughput) on un-anchored network traffic. Also, as shown, the security offload layer includes a group of security instances for security processing (e.g., 95% throughput) on anchored traffic, which can be load-balanced based on Layer 4 information, as described above with respect to Figure 1 (e.g., including multiple PanOS instances, or another commercial virtual / container-based security platform layer may also be implemented in this layer).
[0041] Figure 3 is another functional diagram relating to a system architecture for providing a networking and security split architecture according to several embodiments. Referring to Figure 3, the networking and security split architecture solution 102C (for example, implemented as a cloud-based security service in a virtual private cloud (VPC)) is also provided. It connects network traffic communication to the networking and security split architecture solution 102C via a secure tunnel (for example, a Global Protect (GP) VPN tunnel, provided using the Global Protect (GP) agent commercially available from Palo Alto Networks, Inc., or another secure endpoint agent can be used similarly). As described above with respect to Figure 2, the networking and security split architecture solution 102C includes a networking anchor layer 104C (e.g., implementing layers for routing, networking termination, underlay tunneling, network address translation (NAT), etc.), an offload interface 106 (e.g., implementing layers for providing functional interfaces between the network layer and the security layer), and a security offload layer 108 (a dynamically allocated security processing instance that implements layers for security processing, such as SSL decryption, deep packet inspection (DPI) for security policy enforcement, etc.). As illustrated, the networking anchor layer in this exemplary implementation includes the following exemplary components: a router 114, a VPN gateway 116, and a load balancer 118, as well as a security processing component 120 for performing security processing (e.g., 5% throughput) on non-anchor network traffic.Furthermore, as shown, the security offload layer includes a group of security instances for security processing in anchor traffic (e.g., 95% throughput), which can be load-balanced based on Layer 4 information, as described above with respect to Figure 1 (e.g., including multiple PanOS instances, or another commercial virtual / container-based security platform layer may be implemented in this layer as well).
[0042] In this exemplary implementation (for example, as shown in Figures 2 and / or 3), the security processing performed in both the security processing component of the networking anchor layer and the security offload layer can implement a variety of DPI security processing techniques, including user ID, content ID, and application ID (App-ID) based security processing techniques, as described above (for example, in contrast, in the exemplary implementation of Figure 1, such DPI security processing techniques are performed only in the security offload layer, as described above).
[0043] In this exemplary implementation, metadata between the networking anchor layer and the security offload layer can be encapsulated in the forwarded network traffic. For example, security zone information (e.g., source and destination) can be carried to the security instance when the zone is coupled to the ingress and egress interfaces of the networking anchor layer instance (and other metadata information may also be provided).
[0044] L3 / L4 load balancing
[0045] As described above, the disclosed split architecture facilitates separate network and security processing for performance improvements (for example, high network bandwidth environments can benefit from these performance improvements, as described above). The networking component can handle a variety of networking resources, such as public IPs, private IP pools, Border Gateway Protocol (BGP), and tunneling (e.g., VPN tunneling, etc.), while the security component can also handle various L7 security functions, as described above. In this exemplary implementation, the security component is designed to be resilient in cloud-native environments and, based on our current network test analysis, can handle much higher networking traffic throughput than the security component. Thus, L3 / L4 load balancers are further disclosed to facilitate the efficient redirection of several types of traffic from networking counterparts to the group of security components.
[0046] In one exemplary implementation of the disclosed split architecture system design, the PanOS VM series is used as an anchor instance (for example, alternatively, a third-party or other open-source firewall solution could similarly be used as such an anchor instance). In this exemplary implementation, policy-based forwarding (PBF) is extended to support L3 / L4 load balancers.
[0047] PBF (i.e., policy-based forwarding) is a forwarding function that has a higher priority than routing when making forwarding decisions. Given that not all traffic is necessarily forwarded to security components, PBF can be used to implement traffic filtering. Currently, when using PBF, traffic can only be redirected to a single destination, but to function as a load balancer, this exemplary implementation (e.g., exemplary PanOS VM series implementation) extends this to allow forwarding to a group of next hops (e.g., multipath).
[0048] The following is an exemplary schema for the implementation of the PBF-to-multipath extension disclosed for this exemplary PanOS VM series implementation.
[0049] Schema for PBF to Multipath [Table 1]
[0050] The PBF next hop is the combination of the exit interface from which the packet is sent and the next hop address.
[0051] A PBF multipath group (e.g., a total of 4) is a group of PBF next hops (e.g., up to 64). If a session matches a PBF multipath rule, it is forwarded to the next hop defined in this group based on the hash algorithm defined in that rule.
[0052] The hash algorithm for PBF multipath hashing implementations determines which next hop in a session's traffic can be used as the destination. Currently supported hash algorithms are based on source IP, destination IP, source-destination IP, and session ID.
[0053] As with all other PBF rules, PBF rule matching only occurs for the very first packet of a session to determine the session's exit zone.
[0054] Unlike other types of PBF rules, PBF multipath rules only match c2s traffic. This rule is ignored when performing s2c matching.
[0055] However, if a PBF multipath rule is hit but no active next hop is defined within the multipath group, this rule is ignored, and routing is used instead.
[0056] Thus, the anchor instance can still possess full functionality.
[0057] If a multipath rule is hit and there are active next hops within the group, one of the next hops is selected and cached within the session based on the hash defined in the rule.
[0058] Packets matching this session are forwarded to the selected next hop.
[0059] Furthermore, adding or removing next hops to / from a multipath group generally does not affect existing sessions.
[0060] Performance improvements in networking and security split architectures
[0061] The disclosed networking and security split architectures can facilitate various performance improvements for cloud-based security solutions, as will be explained below.
[0062] For example, regarding the performance of a single remote node (RN), as described above, the performance of a single RN can be improved by offloading the security load to an offload layer.
[0063] Another important aspect is overall performance (cores) per computing power. The disclosed split architecture can enable networking resources to stick to the anchor (outer) layer. This allows cloud-based security services to reduce computing / processing costs at night when traffic is low, without compromising overall performance during the day.
[0064] Thus, the disclosed split architecture facilitates offloading security processing to the inner layer as much as technically feasible. For example, if a ratio greater than 4:1 (inner vs. outer) can be achieved, overall cost savings can be seen without sacrificing performance.
[0065] Figure 7 illustrates one embodiment of the performance improvements provided by a networking and security split architecture according to several embodiments.
[0066] As shown in Figure 7, for example, if one 4-core RN node can handle 250 Mbps of SSL decryption traffic, this RN node can be used to provision one 200 Mbps RN or four 50 Mbps RNs. The total aggregation throughput is 200 Mbps. The throughput per core is 50 Mbps / core. The single highest RN termination is 200 Mbps.
[0067] If FQDN-based scaling is performed without using the disclosed split architecture, four 50Mbps RNs can be separated into four different RN nodes, and then each RN can reach up to 200Mbps. The total aggregation throughput is then 800Mbps. The throughput per core is still 50Mbps / core. The single highest RN termination is still 200Mbps. FQDN-based scaling allows RN scaling up to the capacity that the anchor node can handle. However, FQDN-based scaling cannot scale up further for a single RN instance because of the anchor node capacity limit.
[0068] In contrast, the disclosed split architecture can be used to increase throughput capacity at the anchor node by offloading heavy-lifting SSL decryption traffic to the internal offload layer. Thus, if a 4:1 performance-to-offload ratio can be achieved using the disclosed split architecture, traffic can be processed as follows: one 800Mbps RN or four 200Mbps RNs. In this case, the total aggregation throughput is 800Mbps. The throughput per core is 40Mbps / core. The single highest RN termination is 800Mbps. Thus, the high ceiling of RN capacity is significantly increased, which illustrates how the disclosed split architecture can significantly improve single RN performance.
[0069] Therefore, the disclosed techniques for networking and security split architectures are flexible and can function for any deployment that implements a security instance of the security offload layer using, for example, virtual-based and / or container-based firewalls (e.g., Palo Alto Networks' VM-Series or CN-Series firewalls, or other commercially available virtual-based or container-based firewalls). For example, the disclosed split networking and security architectures can provide a significant throughput boost because all the saved computation cycles can be used for packet processing and additional firewall performance.
[0070] One embodiment of the data appliance 400 is shown in Figure 4A. The example shown is a representation of the physical components that may be included in the network gateway 400 when the network gateway is implemented as a data appliance in various embodiments. Specifically, the data appliance includes a high-performance multi-core central processing unit (CPU) 402 and random access memory (RAM) 404. The data appliance also includes storage 410 (such as one or more hard disks or solid-state storage units). In various embodiments, the data appliance stores information (in RAM 404, storage 410, and / or any other appropriate location) used to monitor the enterprise network and implement the disclosed techniques. Examples of such information include application identifiers, content identifiers, user identifiers, requested URLs, IP address mappings, policy and other configuration information, signatures, hostname / URL classification information, malware profiles, and machine learning models. The data appliance may also include one or more optional hardware accelerators. For example, the data appliance may include a cryptographic engine 406 configured to perform encryption and decryption operations, and one or more field-programmable gate arrays (FPGAs) 408 configured to perform matching, act as a network processor, and / or perform other tasks.
[0071] The functionality described herein as being performed by a data appliance may be provided / implemented in a variety of ways. For example, the data appliance may be a dedicated device or a set of devices. The functionality provided by the data appliance may also be integrated into a general-purpose computer, computer server, gateway, and / or network / routing device, or run there as software. In some embodiments, at least some of the services described as being provided by a data appliance may instead (or additionally) be provided to a client device (an endpoint device, such as a laptop, smartphone, etc.) by software running on the client device.
[0072] Whenever a data appliance is described as performing a task, it may be a single component of the data appliance, a subset of components, or all components working together to perform the task. Similarly, whenever a component of a data appliance is described as performing a task, it may be a subcomponent performing the task, and / or a component performing the task together with other components. In various embodiments, parts of the data appliance are provided by one or more third parties. Depending on factors such as the amount of computing resources available to the data appliance, various logical components and / or features of the data appliance may be omitted, and the techniques described herein may be adapted accordingly. Similarly, additional logical components / features may be included in embodiments of the data appliance where applicable. One example of a component included in a data appliance in various embodiments is an application identification engine configured to identify applications (for example, using various application signatures to identify an application based on packet flow analysis). For example, the application identification engine can determine what types of traffic a session contains, such as web browsing-social networking, web browsing-news, SSH, etc.
[0073] The disclosed system processing architecture can be used with different types of clouds in different deployment scenarios, namely, (1) public clouds, (2) on-premises private clouds, and (3) inside high-end physical firewalls. Some processing power can be allocated to run the private cloud (for example, using a management plane (MP) within a Palo Alto Networks PA-5200 Series firewall appliance).
[0074] Figure 4B is a functional diagram relating to the logical components of one embodiment of the data appliance. The examples shown represent logical components that may be included in the network gateway 400 in various embodiments. Unless otherwise specified, the various logical components of the network gateway 400 can generally be implemented in various ways and are included as a set of one or more scripts (for example, written in Java®, Python, etc., where applicable).
[0075] As shown in the diagram, the network gateway 400 includes a firewall and also includes a management plane 432 and a data plane 434. The management plane is responsible for managing user interactions, such as configuring policies and providing a user interface for viewing log data. The data plane is responsible for managing data, such as performing packet processing and session processing.
[0076] The network processor 436 is configured to receive packets from client devices and provide them to the data plane 434 for processing. The flow module 438 creates a new session flow whenever it identifies a packet as part of a new session. Subsequent packets are identified as belonging to the session based on the flow lookup. Where applicable, SSL decryption is applied by the SSL decryption engine 440. Otherwise, processing by the SSL decryption engine 440 is omitted. The decryption engine 440 can help the network gateway 400 inspect and control SSL / TLS and SSH encrypted traffic, and thus help stop threats that might otherwise remain hidden within encrypted traffic. The decryption engine 440 can also help prevent sensitive content from leaving the enterprise / secure customer network. Decryption can be selectively controlled (e.g., enabled or disabled) based on parameters such as URL category, traffic source, traffic destination, user, user group, and port. In addition to the decryption policy (for example, specifying which sessions to decrypt), the decryption profile can be assigned to control various options for the sessions controlled by the policy. For example, the use of a specific cipher suite and encryption protocol version may be required.
[0077] The Application Identification (APP-ID) engine 442 is configured to determine what type of traffic a session involves. For example, the application identification engine 442 can recognize a GET request in the received data and conclude that the session requires an HTTP decoder. In some cases, such as a web browsing session, the identified application can change, and such changes are recorded by the network gateway 400. For example, a user might first browse a corporate wiki (classified as "Web Browsing - Productivity" based on the visited URL) and then browse a social networking site (classified as "Web Browsing - Social Networking" based on the visited URL). Different types of protocols have corresponding decoders.
[0078] Based on the decision made by the Application Identification (APP-ID) engine 442, the packet is sent by the Threat Engine 444 to an appropriate decoder configured to assemble the packet (which may be received out of order) into the correct order, perform tokenization, and extract information. The Threat Engine 444 also performs signature matching to determine what should happen to the packet. If necessary, the SSL encryption engine 446 can re-encrypt the decrypted data. The packet is then forwarded using the forwarding module 448 for transmission (e.g., to a destination).
[0079] As also shown in Figure 4B, policy 452 is received and stored in the management plane 432. A policy may include one or more rules, which may be specified using a domain and / or host / server name, and the rules may apply one or more signatures, or other matching criteria or heuristics, for example, enforcing a security policy on subscriber / IP flows based on various extracted parameters / information from monitored session traffic flows. Interface (I / F) communicators 450 are provided for management communications (e.g., via (REST) APIs, messages, or network protocol communications or other communication mechanisms).
[0080] Exemplary process embodiment for providing a networking and security split architecture
[0081] Figure 5 is a flowchart showing a process for providing a networking and security split architecture according to several embodiments. In one embodiment, process 500 is performed using the system architecture described above (for example, as described above with respect to Figures 1-4B).
[0082] The process starts with a 502 error when the flow is received by the security service. For example, the security service could be a cloud-based security service, as described above. In one exemplary implementation, the security service is implemented on a virtual-based / container-based network instance (e.g., a VM-series or CN-series firewall, or a third-party network instance or cloud service), and its flow is offloaded for security processing after network processing by the networking anchor layer, as described above (e.g., all or a subset of the overall network traffic passing through the firewall).
[0083] In 504, flow processing is performed at the network layer of the security service to execute one or more networking functions. For example, IPsec termination, network routing, and / or network address translation (NAT) may be performed at the networking anchor layer, as described above.
[0084] In 506, the flow is offloaded to the security layer of a security service in order to perform security enforcement based on the policy. For example, a load balancer in the networking anchor layer can send the flow to a security instance in the security offload layer, as described above.
[0085] Figure 6 is another flowchart illustrating a process for providing a networking and security split architecture according to several embodiments. In one embodiment, process 600 is performed using the system architecture described above (for example, as described above with respect to Figures 1-4B).
[0086] The process starts with a 602 error when multiple flows are received by the security service. For example, the security service could be a cloud-based security service, as described above. In one exemplary implementation, the security service is implemented on a virtual-based / container-based network instance (e.g., a VM-series or CN-series firewall, or a third-party network instance or cloud service), and its flows are offloaded for security processing after network processing by the networking anchor layer, as described above (e.g., all or a subset of the overall network traffic passing through the firewall).
[0087] In 604, flow processing is performed at the network layer of security services to execute one or more networking functions. For example, IPSEC termination, network routing, and / or network address translation (NAT) may be performed at the networking anchor layer, as described above.
[0088] In 606, load balancing of multiple flows is performed to offload the security layer of the security service. For example, the networking anchor layer can include a load balancer, as described above.
[0089] In 608, security checks and enforcement are performed on each of the multiple offloaded flows based on the security service's policy at the security layer. For example, a load balancer at the networking anchor layer can send flows to a security instance at the security offload layer, as described above.
[0090] In version 610, session statistics associated with each of the multiple flows are generated from the security layer, as described above.
[0091] While the embodiments described above have been explained in some detail for the purpose of clarifying understanding, the present invention is not limited to the details provided. Many alternative methods exist for carrying out the present invention. The disclosed embodiments are illustrative and not limiting.
Claims
1. It is a system, Including the processor and memory, The aforementioned processor, In the security service, when a flow is received, To perform one or more networking functions, the network layer of the security service processes the flow, and In order to implement security based on the policy, the aforementioned flow is offloaded to the security layer of the security service, and further, The aforementioned flow is terminated, and The security layer receives session statistics related to the flow, It is configured in such a way, The aforementioned memory is Coupled with the aforementioned processor, and It is configured to provide instructions to the aforementioned processor, The aforementioned flow is determined to be a new flow in the security service. While the network layer of the security service is processing the flow, metadata is extracted from the flow. The aforementioned metadata includes an application identifier associated with the flow, which is encapsulated and transferred between layers. system.
2. Processing the flow at the network layer includes performing IPSEC termination. The system according to claim 1.
3. Processing the flow at the network layer includes performing routing. The system according to claim 1.
4. Processing the flow at the network layer includes performing network address translation (NAT). The system according to claim 1.
5. Processing the flow at the network layer includes using deep packet inspection. The system according to claim 1.
6. The security layer includes multiple security instances, The system according to claim 1.
7. The security layer includes a security instance of a firewall, The system according to claim 1.
8. The security layer includes multiple security instances for separate microservices of security functionality. The security instance includes one or more of the following: antivirus, anti-spam, DNS security, intrusion detection / prevention security (IDS / IPS), and data extraction security. The system according to claim 1.
9. The aforementioned network layer includes a network router, The system according to claim 1.
10. The aforementioned network layer includes a virtual private network (VPN) gateway. The system according to claim 1.
11. The aforementioned network layer includes a load balancer, The system according to claim 1.
12. The aforementioned network layer includes a load balancer, The load balancer sends the first session of the flow to the first security instance of the security layer. The system according to claim 1.
13. The aforementioned network layer includes network anchor instances, The system according to claim 1.
14. The aforementioned security service is a cloud-based security service. The system according to claim 1.
15. The aforementioned security service is a cloud-based security service provided using a public cloud service provider. The system according to claim 1.
16. The aforementioned security service is a cloud-based security service provided using multiple public cloud service providers. The system according to claim 1.
17. It is a method, The data appliance processor performs the steps of receiving flows in the security service, The steps include: processing the flow in the network layer of the security service by the processor in order to perform one or more networking functions; In order to perform security enforcement based on the policy, the processor performs the steps of offloading the flow to the security layer of the security service, The process includes the steps of the processor terminating the flow and receiving session statistics related to the flow from the security layer, Includes, The aforementioned flow is determined to be a new flow in the security service. While the network layer of the security service is processing the flow, metadata is extracted from the flow. The aforementioned metadata includes an application identifier associated with the flow, which is encapsulated and transferred between layers. method.
18. It is a computer program, The aforementioned computer program includes multiple computer instructions and is stored in a non-temporary tangible computer-readable storage medium. When the aforementioned instruction is executed, Steps for receiving flows in security services, The steps include processing the flow at the network layer of the security service in order to perform one or more networking functions, In order to implement security enforcement based on the policy, the steps include offloading the flow to the security layer of the security service, The steps include: terminating the aforementioned flow and receiving session statistics related to the aforementioned flow from the security layer; We will implement the following: The aforementioned flow is determined to be a new flow in the security service. While the network layer of the security service is processing the flow, metadata is extracted from the flow. The aforementioned metadata includes an application identifier associated with the flow, which is encapsulated and transferred between layers. Computer program.