Asymmetric Routing Network Security In-Line Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In high-availability computing environments with asymmetric routing and load balancing, packets may not be properly scanned for viruses due to improper coordination between redundant network security computers, leading to potential virus transmission.

Innovation Solution

A network security computer creates connection information and registers it with another security computer, allowing both inbound and outbound packets to be scanned even in asymmetric routing scenarios, ensuring that both client and server packets are checked for viruses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redundant network security computers are deployed for high-availability scanning, then system reliability is improved, but packet scanning completeness deteriorates due to asymmetric routing coordination issues

Engineering Contradiction:
Improvesystem reliabilityVSAvoidpacket scanning completeness
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent introduces connection tracking information as an intermediary mechanism that mediates between redundant network security computers. This tracking information records which security computer scanned which connection, enabling proper coordination and ensuring packets are scanned by the correct security computer even in asymmetric routing scenarios, thus resolving the contradiction between system reliability and packet scanning completeness

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple security computers scan packets in parallel, then scanning throughput is improved, but coordination complexity increases leading to unscanned packets

Engineering Contradiction:
Improvescanning throughputVSAvoidcoordination complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where each network security computer autonomously checks connection tracking information to determine whether it should scan incoming packets. This eliminates the need for complex inter-computer coordination protocols, allowing parallel scanning operations while maintaining simplicity through self-directed decision-making based on recorded connection state

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7735139B1In-line scanning of network data in an asymmetric routing environment
Publication Date: 2010.06.08 TREND MICRO INC
  • US7735139B1 patent drawing
  • US7735139B1 patent drawing
  • US7735139B1 patent drawing

AI summary

In one embodiment, network data exchanged between a client computer and a remote server computer are scanned for computer viruses at a first network security computer. The first network security computer creates connection information about the connection between the client computer and the server computer, and registers that connection information with a second network security computer that may receive network data transmitted in the connection. This allows the second network security computer to forward to the first network security computer network data transmitted in the connection even when the first and second network security computers are configured for asymmetric routing.