Distributed Firewall Session Table Packet Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional 'bump-in-the-wire' deployment of network security devices is not practical for all data paths in a data center and lacks flexibility for security inspection across different network parts.
Innovation Solution
A distributed firewall mechanism with an input/output function for traffic distribution and a security-processing function for inspection, using a session table to dynamically determine packet forwarding, integrated with existing network equipment like switches and routers, allowing administrators to configure filtering rules and enable/disable security inspection as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional bump-in-the-wire deployment is used to ensure network security inspection, then security coverage is improved, but device complexity and deployment difficulty increase
Solution Approach 1:
The patent combines the security inspection function with existing network equipment (switches, routers, firewalls) by integrating a security inspection module into these devices. This merging approach allows security inspection to be performed without deploying separate dedicated security devices on every data path, thereby maintaining security coverage while reducing deployment complexity.
Solution Approach 2:
The patent enables existing network equipment to perform multiple functions - both their original networking functions and additional security inspection functions. By making network equipment universal and multi-functional, the system achieves broad security coverage without requiring specialized security devices for each inspection point.
2Reliability
If security inspection is performed on all data paths to ensure comprehensive security, then security reliability is improved, but processing efficiency deteriorates due to unnecessary inspections
Solution Approach 1:
The patent implements selective security inspection where different levels of inspection are applied to different packets or data flows based on local characteristics. The security inspection module can identify and apply appropriate inspection strategies for specific packets, performing thorough inspection only when necessary while allowing other packets to pass through with minimal or no inspection, thus maintaining security reliability while improving processing efficiency.
3Reliability
If dedicated security devices are deployed on every data path to ensure security coverage, then security inspection capability is improved, but adaptability to different network configurations deteriorates
Solution Approach 1:
The patent makes network equipment universal by enabling switches, routers, and firewalls to perform security inspection functions in addition to their original networking roles. This multi-functionality allows the system to adapt to different network configurations and topologies without requiring dedicated security devices for each scenario.
Solution Approach 2:
The patent implements dynamic security inspection where the inspection behavior can be adjusted based on network conditions, packet characteristics, and security policies. The security inspection module can dynamically determine whether to inspect packets, what level of inspection to apply, and which packets to allow to bypass inspection, providing adaptability to different network configurations and traffic patterns.
Data Source
AI summary
A network system includes a security device and a network access device. The network access device is to receive a packet from a source node destined to a destination node, and to examine a data structure maintained by the network access device to determine whether the data structure stores a data member having a predetermined value, the data member indicating whether the packet should undergo security processing. If the data member matches the predetermined value, the packet is transmitted to a security device associated with the network access device to allow the security device to perform content inspection, and in response to a response received from the security device, the packet is routed to the destination node dependent upon the response. The packet is routed to the destination node without forwarding the packet to the security device.


