Distributed Firewall Nodes for Real-Time Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall systems in cloud computing lack adaptability and real-time capabilities to identify and mitigate new attacks, as they are centrally managed and fail to respond effectively to emerging threats.

Innovation Solution

A globally distributed firewall system utilizing a network of nodes segregated based on traffic data, category of service, computation capability, and storage capability, with AI techniques for attack detection, pattern generation, and protocol validation to provide real-time threat mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If firewall systems work on centrally stored data, then system management is simplified, but adaptability towards identification and mitigation of new attacks deteriorates

Engineering Contradiction:
Improvesystem managementVSAvoidadaptability towards identification and mitigation of new attacks
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent divides the centralized firewall system into multiple distributed nodes that independently analyze traffic and generate attack patterns. Each node processes local traffic data and contributes to collective threat detection, enabling the system to adapt to new attacks while maintaining manageable complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback mechanisms where detected attack patterns are continuously learned and used to improve future detection accuracy. The distributed nodes share intelligence about new threats, creating a self-improving system that adapts to emerging attack vectors while maintaining systematic coordination

Inventive Principle:
Principle #23Feedback

2Device complexity

If centralized firewall systems are used, then system structure is simplified, but real-time response capability to new attacks deteriorates

Engineering Contradiction:
Improvesystem structureVSAvoidreal-time response capability
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The firewall functionality is segmented across multiple distributed nodes, allowing parallel processing of traffic analysis and attack detection. This distributed architecture enables real-time response to threats while maintaining simplified individual node structures that are easier to manage than a monolithic centralized system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary analysis of traffic patterns and pre-generates attack patterns before actual attacks occur. By continuously monitoring and learning from traffic data in advance, the distributed nodes are prepared to respond immediately when new attacks are detected, achieving real-time response capability

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If distributed nodes are segregated based on multiple parameters, then adaptability to different attack types improves, but device complexity increases

Engineering Contradiction:
Improveadaptability to different attack typesVSAvoidnode segregation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Different nodes are assigned specialized functions based on their capabilities - some nodes excel at detecting specific attack types or processing particular traffic patterns. This local specialization allows the system to adapt to diverse attack types while each node maintains manageable complexity through focused functionality rather than requiring all nodes to handle all threats

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Despite specialization, each distributed node maintains multi-functional capabilities to handle various attack types. The nodes can perform multiple functions including traffic analysis, pattern generation, and threat mitigation, allowing flexible adaptation to different attacks while avoiding the complexity of rigid segregated architectures

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240259400A1System and method for globally distributed firewall protection
Publication Date: 2024.08.01 SHARMA NAVEEN KUMAR
  • US20240259400A1 patent drawing
  • US20240259400A1 patent drawing
  • US20240259400A1 patent drawing

AI summary

Disclosed is a system including a plurality of nodes (102) that includes a first through third sets of nodes (102a-102c). The second set of nodes (102b) detects a type of attack on each node of the first set of nodes (102a), generates a set of attack patterns for the first set of nodes (102b), select one or more attack patterns having a matching score value higher than a pre-defined threshold value, generates a first set of protocols and a second set of protocols. The third set of nodes (102c) checks validity of each protocol of the first set of protocols and the second set of protocols, to generate a set of valid protocols, and distributes the set of valid protocols to each node of the plurality of nodes (102).