Edge Device Autonomic Exclusion via Core Network Cookies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web-based systems, particularly those using Content Delivery Networks (CDNs), face challenges in quickly addressing zero-day attacks due to the geographical dispersal and complexity of reconfiguring edge devices, making it difficult to counter HTTP-borne vulnerabilities effectively.
Innovation Solution
A method where control information, such as an HTTP cookie, is used to dynamically reconfigure edge devices away from the core network to block undesired traffic by originating from the core network security appliances, allowing for indirect communication and dynamic on-the-fly reconfiguration to address network exploits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If edge devices are geographically dispersed to provide CDN functionality, then content delivery throughput is improved, but the ability to quickly reconfigure devices to address security threats deteriorates
Solution Approach 1:
The patent introduces an intermediary mechanism where a core device generates control information (HTTP cookies) that is passed through the client to the edge device. This intermediary approach allows centralized security policy distribution without requiring direct configuration access to geographically dispersed edge devices, thus resolving the contradiction between geographic dispersal for throughput and ease of reconfiguration for security responses.
2Reliability
If direct configuration of edge devices is used to block malicious traffic, then security response effectiveness is improved, but the complexity of managing distributed devices increases
Solution Approach 1:
The patent extracts the security policy generation and management functions from the edge devices and centralizes them in the core device. The core device creates control information (cookies) that encapsulate security policies, which are then distributed to edge devices through clients. This extraction reduces the management complexity at edge devices while maintaining effective security responses.
3Speed
If edge devices are reconfigured in real-time to address zero-day attacks, then reaction speed to threats is improved, but the stability of device configuration deteriorates
Solution Approach 1:
The patent implements dynamic configuration where edge devices can be reconfigured in real-time through control information (HTTP cookies) generated by the core device. The system transitions from static pre-configured security policies to dynamic, on-demand policy distribution. This allows rapid response to zero-day attacks while maintaining configuration stability through standardized cookie-based control mechanisms that don't require permanent device changes.
Data Source
AI summary
An edge device is dynamically reconfigured to block undesired traffic using control information that originates in a core network. The control information is delivered to the device indirectly and, in particular, by a core appliance (e.g., an intrusion prevention system) setting and returning an HTTP cookie to a requesting client. The edge device is pre-configured to respond to HTTP cookies that have (or that are) control information. When the receiving client later returns that cookie to the edge device to obtain subsequent service, the control information that originated at the core is used by the device to deny that service. This indirect method of communicating the control information (from the core to the requesting client and then back to the device) enables the device to be reconfigured dynamically as needed to address network exploits or other threats.


