Application-Context-Aware Firewall for Outbound Connection Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern application servers face security challenges due to malicious programming and rogue connections, which can lead to the exposure of confidential customer information or intellectual property, as traditional firewalls lack context-awareness and require costly deep packet inspection to protect against unauthorized outbound connections.

Innovation Solution

An application-context-aware firewall that intercepts outbound connections, determines the application context, and applies firewall policies based on configured whitelists and blacklists, allowing or blocking connections based on the application and features of the outbound call, thereby protecting against rogue connections and enhancing security without the need for deep packet inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls are used to block unauthorized connections, then basic network security is provided, but they lack context-awareness and require costly deep packet inspection to protect against rogue connections

Engineering Contradiction:
Improvesecurity protectionVSAvoiddeep packet inspection
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an application context-aware firewall that acts as an intermediary layer between traditional firewalls and deep packet inspection. This firewall intercepts outbound connections and uses application context information (such as application identity, connection features, and policy rules) to make blocking decisions, eliminating the need for costly deep packet inspection while maintaining reliable security protection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If deep packet inspection is implemented to detect rogue connections, then security against malicious programming is improved, but processing costs and system complexity increase significantly

Engineering Contradiction:
Improverogue connection detectionVSAvoidprocessing cost
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by establishing application context-aware firewall policies before rogue connections occur. The system pre-configures blocking rules based on application context information, connection features, and security requirements, allowing the firewall to make rapid blocking decisions without performing expensive deep packet inspection during actual connection attempts

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical deep packet inspection process with a more efficient application context-based filtering mechanism. Instead of examining packet contents in detail, the system uses pre-established context-aware rules to determine whether to block connections, significantly reducing processing costs and energy consumption

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If application-context-aware firewall policies are implemented, then granular control over outbound connections is achieved, but policy configuration and management complexity increases

Engineering Contradiction:
Improveconnection control granularityVSAvoidpolicy management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent manages policy configuration complexity by allowing administrators to define blocking rules based on key application context parameters such as application identity, connection features, and target destinations. The system automatically evaluates these parameters against pre-configured policies, providing granular control over outbound connections while simplifying the configuration process through parameter-based rule matching

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10681006B2Application-context-aware firewall
Publication Date: 2020.06.09 CISCO TECHNOLOGY INC
  • US10681006B2 patent drawing
  • US10681006B2 patent drawing
  • US10681006B2 patent drawing

AI summary

In one embodiment, an agent process associated with a particular application on a computing device intercepts outbound connection calls made by the particular application for a remote target host within a computer network, and determines an application context for the outbound connection call based on the particular application and one or more features of the outbound connection call. The agent process may then compare the application context against a set of application-context-aware firewall policies configured on the agent process, and determines whether to allow or not allow (block) the outbound connection call based on the comparing of the application context to the set of application-context-aware firewall policies.