Asymmetric Routing Network Security In-Line Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In high-availability computing environments with asymmetric routing and load balancing, packets may not be properly scanned for viruses due to improper coordination between redundant network security computers, leading to potential virus transmission.
Innovation Solution
A network security computer creates connection information and registers it with another security computer, allowing both inbound and outbound packets to be scanned even in asymmetric routing scenarios, ensuring that both client and server packets are checked for viruses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundant network security computers are deployed for high-availability scanning, then system reliability is improved, but packet scanning completeness deteriorates due to asymmetric routing coordination issues
Solution Approach 1:
The patent introduces connection tracking information as an intermediary mechanism that mediates between redundant network security computers. This tracking information records which security computer scanned which connection, enabling proper coordination and ensuring packets are scanned by the correct security computer even in asymmetric routing scenarios, thus resolving the contradiction between system reliability and packet scanning completeness
2Productivity
If multiple security computers scan packets in parallel, then scanning throughput is improved, but coordination complexity increases leading to unscanned packets
Solution Approach 1:
The patent implements a self-service mechanism where each network security computer autonomously checks connection tracking information to determine whether it should scan incoming packets. This eliminates the need for complex inter-computer coordination protocols, allowing parallel scanning operations while maintaining simplicity through self-directed decision-making based on recorded connection state
Data Source
AI summary
In one embodiment, network data exchanged between a client computer and a remote server computer are scanned for computer viruses at a first network security computer. The first network security computer creates connection information about the connection between the client computer and the server computer, and registers that connection information with a second network security computer that may receive network data transmitted in the connection. This allows the second network security computer to forward to the first network security computer network data transmitted in the connection even when the first and second network security computers are configured for asymmetric routing.


