Context-Based Application Firewall for Dynamic Multitenant Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current application firewall solutions lack the capability to filter based on context-derived information from application logic, making them ineffective in dynamic environments, particularly in multitenant environments where URL parameters and data types vary across tenants, leading to incorrect statistical assumptions and compromised network security.
Innovation Solution
Implementing context-based application firewalls that utilize context information, such as metadata, tenant/organization information, and session information, to make informed security evaluations, allowing for granular decision-making and enhanced security measures like encryption and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional application firewall solutions use keyword searching or statistical models, then they can provide basic filtering capability, but they cannot adapt to dynamic environments with varying URL parameters and data types across tenants
Solution Approach 1:
The patent implements dynamic security rules that adapt to changing application behavior and context. The firewall transitions from static keyword filtering to dynamic rule-based evaluation that responds to real-time application state, user context, and environmental conditions, enabling reliable security decisions in dynamic multitenant environments
Solution Approach 2:
The system changes the parameters used for security evaluation from simple keywords to comprehensive context parameters including user identity, application state, URL parameters, and data types. This parameter transformation enables the firewall to accurately evaluate requests in dynamic environments while maintaining reliability through multi-parameter validation
2Reliability
If application firewalls evaluate entire application behavior at runtime, then they can detect vulnerabilities, but they lack the capability to filter based on context-derived information from application logic
Solution Approach 1:
The patent implements feedback loops where the firewall continuously monitors application behavior, learns from evaluated requests, and refines its security rules. Context information from application logic feeds back into the decision-making process, enabling the system to utilize contextual patterns for more accurate vulnerability detection while maintaining reliability
Solution Approach 2:
The system introduces context information as an intermediary layer between raw requests and security decisions. This intermediary captures and processes application-specific context (user roles, application state, data types) to enhance vulnerability detection accuracy without losing valuable contextual information that would otherwise be unavailable
3Productivity
If firewalls use statistical models of standard usage, then they can identify deviations, but they make incorrect statistical assumptions in multitenant environments with varying URL parameters
Solution Approach 1:
The patent segments the statistical modeling approach by tenant, application, and context type rather than using a single global statistical model. This segmentation allows each tenant and application to have its own baseline statistics, eliminating incorrect assumptions from mixing different URL parameters and data types while maintaining efficient evaluation through pre-computed tenant-specific baselines
Data Source
AI summary
Context-based application firewall functionality. A user session is initiated with a client device. The user session allows access a remote resource on a server device coupled with the client device over a network. The connection between the client device and the remote resource is through an application firewall. An application firewall context setup is performed with the application firewall in response to the user session. The application firewall context comprises firewall context information to be used during the user session to perform network and application security operations with the application firewall. A response is created to provide information from the remote resource to the client device. The response includes metadata to be used to update the firewall context information. The firewall context information is updated with the application firewall based on the metadata. The response is transmitted to the client device.


