Embedded Programmable Packet Filter for Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting computers from malicious network traffic create network bottlenecks and are costly, with traditional firewalls requiring extensive updates and not addressing vulnerabilities quickly enough.

Innovation Solution

Embedding a programmable packet filter within software applications to identify and discard malicious packets, with updates provided via configuration files, eliminating the need for entire application updates and reducing overhead costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall devices are used to filter malicious packets, then application security is improved, but network bottleneck and device complexity increase

Engineering Contradiction:
Improveapplication securityVSAvoidfirewall device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the packet filtering functionality from separate firewall devices and embeds it directly within the application software. This eliminates the need for external firewall hardware while maintaining security filtering capabilities, thereby reducing device complexity and network bottlenecks while preserving application security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent combines the packet filtering function with the application software into a single integrated system. By merging the firewall filtering capabilities directly into the application, the system eliminates the need for separate firewall devices and reduces network traffic routing complexity while maintaining security protection.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If specialized firewall devices are deployed to protect multiple applications, then security coverage is improved, but cost increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcost
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent implements a universal packet filtering mechanism embedded within each application that can handle multiple types of security threats. This multi-functional approach allows a single application to provide its own security filtering without requiring separate specialized firewall devices for each application, thereby reducing overall cost while maintaining broad security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables each application to filter its own incoming packets using embedded filtering logic. This self-service approach eliminates the need for expensive centralized firewall devices to protect each application individually, allowing applications to autonomously protect themselves while maintaining comprehensive security coverage across multiple applications.

Inventive Principle:
Principle #25Self-service

3Loss of time

If application vendors release patches quickly to fix vulnerabilities, then vulnerability response time is improved, but deployment complexity increases

Engineering Contradiction:
Improvevulnerability response timeVSAvoiddeployment complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent segments the security filtering functionality into a separate, independently updatable component within the application. This allows vulnerability patches to be applied only to the filtering module without requiring updates to the entire application, thereby reducing deployment complexity while enabling rapid response to new vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary security filtering capabilities embedded within the application that can be updated independently of the main application code. This allows vendors to quickly deploy security patches for emerging threats without waiting for full application updates, reducing vulnerability response time while simplifying the deployment process through modular updates.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8037532B2Application protection from malicious network traffic
Publication Date: 2011.10.11 A10 NETWORKS INC
  • US8037532B2 patent drawing
  • US8037532B2 patent drawing
  • US8037532B2 patent drawing

AI summary

A program, method and system for embedding a programmable packet filter into an application to protect the application against malicious network packets are disclosed. Traditional packet filtering techniques to protect against malicious packets designed to exploit defects in applications, based on external packet filtering devices create a bottleneck in network traffic and present a large overhead cost. In addition, when security vulnerabilities in applications are discovered, traditional application updating methods lack a fast enough turn-around time to protect the application and users data from attack. These problems can be overcome by embedding a programmable packet filter into the application itself. The application can use the filter to discard malicious network packets. Furthermore, the filter can be updated via configuration files downloaded from the application vendor to update the application's embedded programmable packet filter without having to update the entire program code of the application.