Federated Firewall Security Matrix Offloads Functions to End Hosts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewalls face challenges such as insufficient computing power, limited visibility into traffic, inability to detect internal threats, and inefficiencies due to end-to-end encryption, leading to scalability and effectiveness issues in handling sophisticated cyber-attacks.

Innovation Solution

A federated firewall security system that offloads selected firewall functions to end hosts, leveraging a centralized security matrix to distribute and coordinate firewall operations across the network, enhancing scalability and effectiveness by utilizing local security capabilities and improving threat detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Next Generation Firewall (NGFW) inspection and detection capabilities are enhanced, then security effectiveness against cyber-attacks is improved, but computational and memory costs increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidcomputational and memory costs
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the firewall system into multiple distributed firewall agents deployed across different network devices and end hosts, rather than relying on a single centralized NGFW. This segmentation distributes the computational and memory workload across multiple nodes, reducing the burden on any single device while maintaining enhanced inspection capabilities through coordinated security policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized security management server as an intermediary that coordinates security policies and manages communication between distributed firewall agents. This intermediary handles complex inspection logic centrally while allowing local agents to perform filtering operations, balancing the need for advanced detection with reduced computational overhead at network perimeter devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a single firewall handles all network traffic inspection, then security policy enforcement is centralized, but scalability and performance deteriorate under high traffic loads

Engineering Contradiction:
Improvecentralized policy enforcementVSAvoidscalability and performance
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The firewall functionality is segmented into multiple distributed agents deployed across network devices, routers, and end hosts. Each agent enforces security policies locally for its assigned traffic, enabling the system to scale horizontally by adding more agents without overloading a single firewall device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimension centralized firewall architecture to a multi-dimensional distributed architecture where security enforcement occurs at multiple levels (network perimeter, intermediate devices, and end hosts). This dimensional expansion allows traffic to be inspected and filtered at various points in the network, improving scalability while maintaining centralized policy management.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Use of energy by moving object

If firewall functions are distributed to end hosts, then computational burden on firewalls is reduced, but system complexity and trust verification requirements increase

Engineering Contradiction:
Improvecomputational burden on firewallVSAvoidsystem complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where distributed firewall agents continuously report their status, capability information, and security events to the centralized security management server. The server verifies trust levels and capability information from agents, dynamically adjusting security policies and coordinating actions across the distributed system, thereby managing complexity through structured communication and verification protocols.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

End hosts equipped with firewall agents perform self-service security functions by locally inspecting and filtering their own traffic according to distributed security policies. This self-service capability reduces the computational burden on centralized firewalls while the standardized agent architecture and centralized coordination keep system complexity manageable.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10021070B2Method and apparatus for federated firewall security
Publication Date: 2018.07.10 CISCO TECHNOLOGY INC
  • US10021070B2 patent drawing
  • US10021070B2 patent drawing
  • US10021070B2 patent drawing

AI summary

In one embodiment, a method includes receiving capability information from an end host at a centralized security matrix in communication with a firewall and a plurality of end hosts, verifying at the centralized security matrix, a trust level of the end host, assigning at the centralized security matrix, a firewall function to the end host based on the trust level and capability information, and notifying the firewall of the firewall function assigned to the end host. Firewall functions are offloaded from the firewall to the end hosts by the centralized security matrix. An apparatus and logic are also disclosed herein.