Distributed WAF Cluster Segmentation for Latency Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional web application firewalls (WAFs) are inflexible, resource-intensive, and error-prone when manually deployed across entire business infrastructures, often providing unnecessary latency and security benefits, as they use a single rule base for all software applications, which may not require the same level of protection.

Innovation Solution

A distributed WAF cluster infrastructure is configured and validated to support specific protected applications, using container orchestration tools like Kubernetes for self-service, automated upgrades, scalability, and self-healing, with tailored rulesets for each application, reducing latency and false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single rule base is used for all software applications in a traditional WAF, then security coverage is comprehensive, but latency increases and false positives occur due to unnecessary filtering rules

Engineering Contradiction:
Improvesecurity coverageVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the monolithic WAF rule base into multiple application-specific rule sets. Each protected application receives a tailored rule set that contains only the filtering rules relevant to its specific security requirements, eliminating unnecessary rules that cause latency and false positives while maintaining comprehensive security coverage for each application.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by customizing security rules for each specific application based on its unique characteristics and risk profile. Instead of applying a uniform rule base across all applications, the system tailors the security filtering behavior to match the local requirements of each protected application, optimizing both security effectiveness and performance.

Inventive Principle:
Principle #3Local quality

2Reliability

If manual deployment of WAFs is used across entire business infrastructure, then security protection is provided, but the process is inflexible, resource demanding, and error prone

Engineering Contradiction:
Improvesecurity protectionVSAvoiddeployment flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling applications to automatically provision and configure their own WAF protection. The system allows applications to self-register, automatically receive appropriate rule sets, and manage their own security configurations without requiring manual intervention from security administrators, thereby improving deployment flexibility and reducing errors.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring application-specific rule sets and security policies before deployment. The system prepares tailored rule sets in advance based on application metadata and security requirements, so that when applications are deployed, they immediately receive appropriate protection without requiring manual rule configuration during the deployment process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional WAFs are deployed in front of entire business infrastructure, then security coverage is broad, but resource consumption increases and flexibility decreases

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the WAF infrastructure into distributed, application-specific instances rather than a single monolithic deployment. Each protected application has its own WAF instance with a customized rule set, which reduces the computational resources required per instance by processing only relevant traffic and rules, thereby lowering overall resource consumption while maintaining broad security coverage.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11677716B2System of a distributed web application firewall cluster
Publication Date: 2023.06.13 DELL PROD LP
  • US11677716B2 patent drawing
  • US11677716B2 patent drawing
  • US11677716B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for management of a distributed web application firewall (WAF) cluster that supports one or more protected applications. A WAF cluster infrastructure is configured for the protected applications. The WAF cluster includes one or more WAFs that are used to route traffic directed to the protected applications. The WAF cluster infrastructure is validated as to be current and updated. The validated WAF cluster infrastructure is then used as routing service.