Edge Network Security with Selective Traffic Suspension
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security solutions that migrate to edge security face a tradeoff between costly processing power and increased throughput, often resulting in sub-standard security, particularly due to inefficient use of wide area network (WAN) bandwidth and unnecessary security processing for low-risk traffic.
Innovation Solution
Implementing selectively suspended network security processing, where a non-edge security processing device applies intensive security processing to a subset of network traffic, allowing edge devices to suspend security review for less risky traffic, thereby reducing the need for WAN bandwidth and lowering costs by eliminating unnecessary security inspections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If intensive security processing is applied to all network traffic at the edge, then security effectiveness is improved, but processing cost and device complexity increase
Solution Approach 1:
The patent applies different security processing levels to different portions of network traffic based on risk assessment. High-risk traffic receives intensive security processing while low-risk traffic receives reduced processing, creating localized quality variations in security enforcement that optimize both security effectiveness and processing cost.
Solution Approach 2:
The patent implements partial security processing by applying intensive security measures only to identified high-risk traffic portions rather than all traffic. This partial action approach maintains security effectiveness for critical traffic while reducing overall processing complexity and cost.
2Reliability
If intensive security processing is applied to all network traffic, then security effectiveness is improved, but WAN bandwidth usage increases
Solution Approach 1:
The patent selectively applies security processing to local high-risk traffic portions identified through risk assessment, allowing low-risk traffic to bypass intensive processing. This local quality approach reduces WAN bandwidth consumption while maintaining security effectiveness for critical traffic segments.
Solution Approach 2:
The patent extracts and identifies high-risk traffic portions from the overall network traffic flow, separating them for intensive security processing while allowing the remaining low-risk traffic to flow with reduced processing requirements, thereby reducing WAN bandwidth usage.
3Reliability
If security review is performed on all network traffic sessions, then security effectiveness is improved, but throughput decreases
Solution Approach 1:
The patent implements local quality by applying full security review only to identified high-risk traffic sessions while reducing or suspending security review for low-risk sessions. This creates varying levels of security processing across different traffic portions, maintaining security effectiveness for critical traffic while improving overall throughput.
Solution Approach 2:
The patent applies partial security review action to network traffic by suspending security processing for portions of traffic sessions deemed low-risk after initial assessment. This partial action maintains security for high-risk traffic while eliminating unnecessary processing overhead for low-risk traffic, thereby improving throughput.
Data Source
AI summary
Various embodiments provide embodiments provide systems and methods for performing edge processing using selectively suspended network security processing.


