Context-Aware Client Firewall for Mobile Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current client firewalls for mobile devices are naive and lack intelligent context, making them ineffective in filtering network traffic for cloud-based applications with dynamic IP addresses, leading to increased security risks and vulnerabilities in enterprise networks.

Innovation Solution

A context-aware client firewall that intercepts all network traffic, derives static and dynamic risk profiles based on parameters like geolocation and network type, and computes an overall risk to granularly control and block or allow traffic, using a cloud security system for evaluation and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional layer 2 firewalls are used to block specific IPs and ports, then network access can be limited, but they fall dramatically short to filter cloud-based traffic with dynamic IP addresses

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidability to filter dynamic IP traffic
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the filtering parameters from static IP addresses and ports to dynamic parameters including cloud service identifiers, application layer protocols, and contextual attributes. This allows the firewall to effectively filter cloud-based traffic that uses dynamic IP addresses by matching traffic patterns and service characteristics rather than relying on fixed network layer identifiers.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The firewall transitions from a static filtering mechanism to a dynamic one that adapts to changing cloud service IP addresses. The system continuously updates its filtering rules based on observed traffic patterns, service identification, and contextual information, enabling it to maintain security effectiveness despite the dynamic nature of cloud infrastructure.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If IP address subnet and multiple inbound ports are allowed to address cloud-based hosting, then security is weakened, but this introduces additional overhead to manage

Engineering Contradiction:
Improvecompatibility with cloud servicesVSAvoidmanagement overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The firewall system performs automatic service identification and rule generation without requiring manual configuration of extensive IP subnets and ports. The cloud service identifier and application layer protocol detection capabilities enable the system to self-configure appropriate filtering rules, significantly reducing management overhead while maintaining compatibility with cloud-based hosting services.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If current state-of-the art client firewalls are used, then basic filtering is provided, but they lack intelligent context which leads to broader attack surface

Engineering Contradiction:
Improvebasic filtering capabilityVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms that collect and analyze contextual information about network traffic, device state, and user behavior. This feedback is used to dynamically adjust filtering decisions, enabling the firewall to distinguish between legitimate and malicious traffic more effectively, thereby reducing the attack surface while maintaining ease of operation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The firewall extends beyond traditional network layer filtering by incorporating application layer protocol analysis, cloud service identification, and contextual attributes. This dimensional expansion adds intelligence to basic filtering, enabling more precise traffic control that reduces the attack surface without complicating operation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20240146689A1Context Aware Client Firewall for Mobile Devices in Cloud Security Systems
Publication Date: 2024.05.02 ZSCALER INC
  • US20240146689A1 patent drawing
  • US20240146689A1 patent drawing
  • US20240146689A1 patent drawing

AI summary

Systems and methods for providing a context aware client firewall. Various embodiments include intercepting all network traffic to and from a mobile device, deriving a static risk profile of the mobile device based on one or more parameters, determining a dynamic risk of the mobile device based on network flow attributes, and computing an overall risk for the network traffic based on the static risk profile and the dynamic risk. Network traffic can therefore be allowed or blocked based on the computed risk. The solution provides granular control to IT administrations to block network traffic based on parameters such as geolocation, network type, and various others described herein.