Edge Firewall Deep Packet Inspection for Early Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional layered network security approaches fail to provide early detection and prevention of intrusion incidents, expose key network elements to malicious attacks, lack analysis of traffic flow from a session layer perspective, and struggle with scalability and coordination across multiple devices.

Innovation Solution

An application layer firewall function with integrated deep packet inspection is implemented at an edge networking device, allowing for early intrusion detection and prevention by strategically placing intrusion detection and prevention systems within the session controller, enabling real-time security policy enforcement and adaptation across the OSI layer stack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If independent point solutions with separate DPI/firewall devices are used, then security coverage is provided, but device complexity and coordination requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions (DPI, firewall, intrusion detection, intrusion prevention) into a single integrated security device, eliminating the need for multiple separate devices and reducing coordination complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security device is designed to perform multiple security functions simultaneously including deep packet inspection, firewall filtering, intrusion detection, and intrusion prevention, allowing a single device to provide comprehensive security coverage that previously required multiple specialized devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security devices are placed at various locations in the network, then maximum security coverage is achieved, but loss of time due to multiple coordination points increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcoordination time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By consolidating security functions into a single device located at the network edge, the patent eliminates the need for coordination between multiple geographically distributed security devices, reducing communication overhead and response time while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If deep packet inspection is performed externally to SBC, then security filtering is provided, but early intrusion detection capability is reduced

Engineering Contradiction:
Improvesecurity filteringVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security device performs deep packet inspection and intrusion detection at the network edge before traffic enters the core network or reaches the SBC, enabling early detection and blocking of malicious traffic before it can compromise internal systems

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple discrete security devices are deployed, then comprehensive security functions are provided, but scalability and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity functionsVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent integrates multiple security functions into a single device with unified management and configuration interfaces, significantly improving ease of operation and deployment compared to managing multiple discrete security devices, while maintaining comprehensive security functionality

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8307418B2Methods, systems, and computer readable media for providing application layer firewall and integrated deep packet inspection functions for providing early intrusion detection and intrusion prevention at an edge networking device
Publication Date: 2012.11.06 RIBBON COMMUNICATIONS OPERATING CO INC
  • US8307418B2 patent drawing
  • US8307418B2 patent drawing
  • US8307418B2 patent drawing

AI summary

Methods, systems, and computer readable media for an application layer firewall function including an integrated deep packet inspection function for providing early intrusion detection and intrusion prevention at an edge networking device are disclosed. According to one method, steps are performed at a session controller configured to operate at the border of a first network and a second network. The steps include receiving, at an intrusion protection system (IPS) module of the session controller interfacing with modules associated with layers 2 and above of a protocol stack of the session controller, information gathered by modules located at lower layers and associated with an intrusion attempt, vulnerability, or other security policy violation. In response to receiving the information, the IPS module provides at least one of a security policy and a rule to a module located at the most appropriate layer for securing the intrusion attempt, vulnerability, or other security policy violation.