Data Relay Device Security Rule Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data relay devices with multiple security functions face increased load and reduced throughput due to unnecessary execution of security processes, especially when a security problem is detected, leading to inefficiencies and performance degradation.
Innovation Solution
A data relay device that executes security functions in a predetermined order and uses a determination result to change rules for subsequent processes, skipping unnecessary steps by denying relay and updating rules to avoid executing subsequent security functions on problematic data from specific sources, thereby reducing the load and improving throughput.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security functions are executed sequentially on inputted data, then security coverage is improved, but device load increases and throughput decreases
Solution Approach 1:
The patent applies preliminary action by executing security functions in a predetermined sequence and stopping further execution once a security problem is detected. The system performs firewall processing, then anti-virus processing, then spam filtering in order, and halts subsequent processing when an issue is found in earlier stages, preventing unnecessary execution of later security functions on already problematic data
Solution Approach 2:
The patent implements skipping by allowing the data relay device to bypass remaining security function executions when a security problem is detected in earlier functions. Instead of sequentially executing all planned security functions, the system skips the remaining ones after detecting an issue, thereby reducing device load while maintaining security effectiveness
2Measurement precision
If all security functions are executed on every data packet, then security detection accuracy is improved, but processing time increases
Solution Approach 1:
The system performs preliminary security checks in a predetermined sequence (firewall → anti-virus → spam filtering) and stops further processing once a security issue is detected in an earlier stage, preventing waste of processing time on packets that already have identified security problems
Solution Approach 2:
When a security problem is detected in earlier security functions, the system skips execution of subsequent security functions on that data packet, thereby reducing processing time while maintaining detection accuracy through the sequential execution of necessary checks
Data Source
AI summary
A data relay device has a plurality of security functions sequentially executes security functions on inputted data based on a predetermined rule, to determine whether or not to permit the relay of the data, and denies the relay of the data the relay is determined to be rejected. The data relay device has a determination result acquisition unit that acquires a determination result indicating permission or rejection of relay of the data, and a rule change unit that changes, based on the determination result acquired by the determination result acquisition unit, a rule defined for any one of the security functions located forward of the security function that has determined relay rejection, so that the relay of the communication data is determined to be rejected.


