Distributed Firewall Gateway Host-Based Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network gateway security systems are limited in controlling malicious behavior on mobile devices, as they only provide network-based protection, while host-based systems consume significant resources and are inefficient in detecting coordinated threats across multiple devices.

Innovation Solution

A distributed firewall system that monitors network traffic between a network gateway and clients, activates host-based protection measures when threat levels exceed a predetermined range, combining network-based and host-based security measures to obstruct undesired behavior and gather additional information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host-based security systems are implemented on network clients, then security protection effectiveness is improved, but device resource consumption (memory, computing time, power) increases significantly

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security system is divided into two segments: a lightweight network-based monitoring component at the gateway and a host-based protection component on the client device. The network gateway performs initial traffic analysis and threat level assessment, while host-based measures are only activated when threats are detected, segmenting the security functions to optimize resource usage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security system dynamically adjusts its operation mode based on threat levels. The network gateway continuously monitors traffic and adjusts the client threat-level metric in real-time. Host-based protection measures are dynamically activated or deactivated based on whether the threat-level exceeds predetermined thresholds, allowing the system to adapt resource consumption to actual security needs.

Inventive Principle:
Principle #15Dynamics

2Reliability

If host-based security systems are implemented on network clients, then security protection effectiveness is improved, but battery life on mobile devices decreases

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidbattery life
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

Instead of continuous host-based monitoring, the system uses periodic network-based monitoring at the gateway and only activates host-based measures periodically when threat levels indicate a need. This periodic activation pattern reduces continuous power consumption while maintaining security effectiveness.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The network gateway autonomously monitors network traffic and independently determines when host-based protection should be activated based on detected traffic patterns and calculated threat levels. This self-service approach eliminates the need for continuous client-side resource consumption while maintaining security.

Inventive Principle:
Principle #25Self-service

3Use of energy by moving object

If network gateway security systems are used, then resource consumption on client devices is reduced, but control over malicious behavior on client devices is limited

Engineering Contradiction:
Improveresource consumptionVSAvoidcontrol over malicious behavior
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The network gateway acts as an intermediary that bridges network-based monitoring and host-based protection. It analyzes network traffic, calculates threat levels, and mediates between the network environment and the client device by transmitting action commands to activate host-based measures when needed, combining the advantages of both approaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback loop where the network gateway continuously monitors network traffic, calculates client threat-levels based on detected patterns, and transmits action commands back to client devices when threats are detected. This feedback mechanism ensures continuous control and adaptation without requiring constant client-side resource consumption.

Inventive Principle:
Principle #23Feedback

4Reliability

If host-based security systems are implemented, then detection of local threats is improved, but coordinated threat detection across multiple devices is not achieved

Engineering Contradiction:
Improvelocal threat detectionVSAvoidcoordinated threat detection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system merges network-based monitoring at the gateway with host-based protection on individual devices. The gateway aggregates traffic data from multiple clients, calculates threat levels, and coordinates activation of host-based measures across devices, achieving both local detection capability and coordinated multi-device threat response.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11140129B2Distributed firewall system
Publication Date: 2021.10.05 CYAN SECURITY GRP GMBH
  • US11140129B2 patent drawing
  • US11140129B2 patent drawing
  • US11140129B2 patent drawing

AI summary

A method and system comprising a network gateway for monitoring a network traffic between a network client and the network gateway, and at least one network client connected to said network gateway and comprising means for applying host-based protection measures are provided, wherein the network gateway evaluates the monitored traffic for indications of undesired behaviour and has control of the means for applying host-based protection measures of the at least one network client. Optionally network-based protection measures activated at the network gateway may be combined with the host-based protection measures and/or suspicious device events observed at the network client may be accounted for when assessing suitable protection measures in addition to the traffic monitored at the network gateway.