Distributed Firewall Session Table Packet Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional 'bump-in-the-wire' deployment of network security devices is not practical for all data paths in a data center and lacks flexibility for security inspection across different network parts.

Innovation Solution

A distributed firewall mechanism with an input/output function for traffic distribution and a security-processing function for inspection, using a session table to dynamically determine packet forwarding, integrated with existing network equipment like switches and routers, allowing administrators to configure filtering rules and enable/disable security inspection as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional bump-in-the-wire deployment is used to ensure network security inspection, then security coverage is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvenetwork security coverageVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the security inspection function with existing network equipment (switches, routers, firewalls) by integrating a security inspection module into these devices. This merging approach allows security inspection to be performed without deploying separate dedicated security devices on every data path, thereby maintaining security coverage while reducing deployment complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enables existing network equipment to perform multiple functions - both their original networking functions and additional security inspection functions. By making network equipment universal and multi-functional, the system achieves broad security coverage without requiring specialized security devices for each inspection point.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security inspection is performed on all data paths to ensure comprehensive security, then security reliability is improved, but processing efficiency deteriorates due to unnecessary inspections

Engineering Contradiction:
Improvesecurity inspection reliabilityVSAvoidpacket processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements selective security inspection where different levels of inspection are applied to different packets or data flows based on local characteristics. The security inspection module can identify and apply appropriate inspection strategies for specific packets, performing thorough inspection only when necessary while allowing other packets to pass through with minimal or no inspection, thus maintaining security reliability while improving processing efficiency.

Inventive Principle:
Principle #3Local quality

3Reliability

If dedicated security devices are deployed on every data path to ensure security coverage, then security inspection capability is improved, but adaptability to different network configurations deteriorates

Engineering Contradiction:
Improvesecurity inspection capabilityVSAvoidnetwork configuration adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes network equipment universal by enabling switches, routers, and firewalls to perform security inspection functions in addition to their original networking roles. This multi-functionality allows the system to adapt to different network configurations and topologies without requiring dedicated security devices for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic security inspection where the inspection behavior can be adjusted based on network conditions, packet characteristics, and security policies. The security inspection module can dynamically determine whether to inspect packets, what level of inspection to apply, and which packets to allow to bypass inspection, providing adaptability to different network configurations and traffic patterns.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8955093B2Cooperative network security inspection
Publication Date: 2015.02.10 GRYPHO5 LLC
  • US8955093B2 patent drawing
  • US8955093B2 patent drawing
  • US8955093B2 patent drawing

AI summary

A network system includes a security device and a network access device. The network access device is to receive a packet from a source node destined to a destination node, and to examine a data structure maintained by the network access device to determine whether the data structure stores a data member having a predetermined value, the data member indicating whether the packet should undergo security processing. If the data member matches the predetermined value, the packet is transmitted to a security device associated with the network access device to allow the security device to perform content inspection, and in response to a response received from the security device, the packet is routed to the destination node dependent upon the response. The packet is routed to the destination node without forwarding the packet to the security device.