Context-Aware Client Firewall for Mobile Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current client firewalls for mobile devices are naive and lack intelligent context, making them ineffective in filtering network traffic for cloud-based applications with dynamic IP addresses, leading to increased security risks and vulnerabilities in enterprise networks.
Innovation Solution
A context-aware client firewall that intercepts all network traffic, derives static and dynamic risk profiles based on parameters like geolocation and network type, and computes an overall risk to granularly control and block or allow traffic, using a cloud security system for evaluation and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional layer 2 firewalls are used to block specific IPs and ports, then network access can be limited, but they fall dramatically short to filter cloud-based traffic with dynamic IP addresses
Solution Approach 1:
The patent changes the filtering parameters from static IP addresses and ports to dynamic parameters including cloud service identifiers, application layer protocols, and contextual attributes. This allows the firewall to effectively filter cloud-based traffic that uses dynamic IP addresses by matching traffic patterns and service characteristics rather than relying on fixed network layer identifiers.
Solution Approach 2:
The firewall transitions from a static filtering mechanism to a dynamic one that adapts to changing cloud service IP addresses. The system continuously updates its filtering rules based on observed traffic patterns, service identification, and contextual information, enabling it to maintain security effectiveness despite the dynamic nature of cloud infrastructure.
2Adaptability or versatility
If IP address subnet and multiple inbound ports are allowed to address cloud-based hosting, then security is weakened, but this introduces additional overhead to manage
Solution Approach 1:
The firewall system performs automatic service identification and rule generation without requiring manual configuration of extensive IP subnets and ports. The cloud service identifier and application layer protocol detection capabilities enable the system to self-configure appropriate filtering rules, significantly reducing management overhead while maintaining compatibility with cloud-based hosting services.
3Ease of operation
If current state-of-the art client firewalls are used, then basic filtering is provided, but they lack intelligent context which leads to broader attack surface
Solution Approach 1:
The patent implements feedback mechanisms that collect and analyze contextual information about network traffic, device state, and user behavior. This feedback is used to dynamically adjust filtering decisions, enabling the firewall to distinguish between legitimate and malicious traffic more effectively, thereby reducing the attack surface while maintaining ease of operation.
Solution Approach 2:
The firewall extends beyond traditional network layer filtering by incorporating application layer protocol analysis, cloud service identification, and contextual attributes. This dimensional expansion adds intelligence to basic filtering, enabling more precise traffic control that reduces the attack surface without complicating operation.
Data Source
AI summary
Systems and methods for providing a context aware client firewall. Various embodiments include intercepting all network traffic to and from a mobile device, deriving a static risk profile of the mobile device based on one or more parameters, determining a dynamic risk of the mobile device based on network flow attributes, and computing an overall risk for the network traffic based on the static risk profile and the dynamic risk. Network traffic can therefore be allowed or blocked based on the computed risk. The solution provides granular control to IT administrations to block network traffic based on parameters such as geolocation, network type, and various others described herein.


