Cloud Stream Scanner for Perimeter-less Network Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Intrusion Prevention Systems (IPS) and firewalls are inadequate in protecting mobile devices and cloud-based environments due to their physical appliance-based design, which limits their ability to capture and protect against threats in perimeter-less networks, especially where user devices are involved, and they struggle with inspecting SSL-encrypted traffic where most threats reside.

Innovation Solution

A cloud-based Intrusion Prevention System (IPS) and multi-tenant firewall system that uses a Snort-like format for writing signatures to analyze data traffic, providing stream-based filter patterns and match rules, enabling real-time traffic analysis and packet logging, and offering threat protection across various connection types, devices, and operating systems, while eliminating the need for physical appliances and scaling inspection demands automatically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional physical IPS appliances are used, then intrusion detection and prevention functions are provided, but the system cannot protect mobile devices and cloud-based environments due to physical appliance design limitations

Engineering Contradiction:
Improveadaptability to mobile and cloud environmentsVSAvoidphysical appliance-based design
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces physical IPS appliances with a cloud-based virtualized security system. Instead of relying on hardware appliances deployed at network perimeters, the invention delivers intrusion prevention capabilities through cloud-based agents and services that can operate on mobile devices, laptops, and in cloud environments, effectively substituting mechanical/physical systems with software-based cloud services.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The cloud-based IPS system provides universal protection across multiple platforms and environments (mobile devices, laptops, cloud services, traditional networks) through a unified architecture. The system can adapt to different connection types, operating systems, and device forms factors, making it versatile and applicable to diverse security scenarios beyond what traditional physical appliances could achieve.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If conventional firewalls are deployed at network boundaries, then traffic filtering is provided, but protection is unavailable for users outside the internal network

Engineering Contradiction:
Improveprotection coverage for remote usersVSAvoiddeployment simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The invention replaces traditional network boundary firewalls with cloud-based security services that follow users wherever they connect. Instead of requiring physical firewall appliances at every location or complex host-based firewall configurations on each device, the system delivers firewall capabilities through cloud-based agents and services that automatically protect users whether they are in the office, remote, or using mobile devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The cloud-based system automatically provisions and manages security protection for users without requiring manual deployment of physical appliances or complex configuration. The system self-adapts to user devices and environments, automatically detecting connection types, operating systems, and device characteristics to provide appropriate protection, eliminating the need for users to manually configure firewalls at each location.

Inventive Principle:
Principle #25Self-service

3Reliability

If physical IPS appliances are used, then intrusion prevention is provided at the data center, but the system runs blind to threats in perimeter-less networks

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcoverage in perimeter-less networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces data center-anchored physical IPS appliances with a cloud-based system that provides continuous threat protection regardless of user location or network perimeter. The cloud-based architecture enables the system to detect and respond to threats in perimeter-less environments such as mobile networks, cloud services, and remote connections, where traditional perimeter-based security cannot operate effectively.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11159486B2Stream scanner for identifying signature matches
Publication Date: 2021.10.26 ZSCALER INC
  • US11159486B2 patent drawing
  • US11159486B2 patent drawing
  • US11159486B2 patent drawing

AI summary

System and methods implemented in a node in a cloud-based security system include obtaining a plurality of rules each define via a rule syntax that includes a rule header and rule options, wherein each rule header is used to for a rule database lookup, and each rule options is used to specify details about the associated rule; monitoring data associated with a user of the cloud-based security system; analyzing the data with the plurality of rules; and performing one or more security functions on the data based on triggering of a rule of the plurality of rules.