Firewall Session APP ID Correlation With Endpoint Process ID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing advanced or next generation firewalls lack process/application information at the endpoint device, limiting their ability to implement fine-grained security policies and effectively detect and block sophisticated attack vectors, such as malware evasions and rootkits.

Innovation Solution

Techniques for correlating session application identification (APP ID) with endpoint process identification (EP process ID) to enhance firewall policy enforcement, using trusted agents on endpoints to monitor and communicate process information to the firewall, enabling fine-grained security policies and detecting abnormal network sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall policies are used without process ID correlation, then device complexity is reduced, but security reliability is insufficient due to inability to detect sophisticated attack vectors

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism that correlates session APP ID with endpoint process ID to bridge the gap between network-level firewall filtering and application-level process control. This correlation layer enables sophisticated security policies without requiring complete redesign of the firewall architecture, thus improving reliability while controlling complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security enforcement into multiple layers: network-level APP ID filtering and endpoint-level process ID verification. This segmentation allows each layer to handle specific aspects of security, improving overall reliability while distributing complexity across different components rather than concentrating it in a single complex system

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If fine-grained security policies are implemented using process ID correlation, then security detection capability is improved, but computational overhead increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidcomputational overhead
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by selectively correlating process IDs only for sessions that require fine-grained security inspection, rather than performing full process ID correlation on all network traffic. This selective approach enhances detection capability for suspicious traffic while minimizing unnecessary computational overhead on legitimate traffic

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary action by establishing process ID correlation mechanisms in advance and maintaining cached process information at the endpoint. This preliminary setup enables faster real-time detection without requiring intensive computational resources during actual security inspection, thus improving detection capability while reducing ongoing computational overhead

Inventive Principle:
Principle #10Preliminary action

3Reliability

If all network sessions are inspected for process ID correlation, then security monitoring is comprehensive, but processing time increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements partial monitoring by focusing process ID correlation and security inspection efforts on sessions that exhibit suspicious characteristics or match known attack patterns, rather than uniformly inspecting all sessions. This approach maintains comprehensive security monitoring for critical threats while reducing processing time for routine traffic

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3682325B1Fine-grained firewall policy enforcement using session APP id and endpoint process id correlation
Publication Date: 2025.11.05 PALO ALTO NETWORKS INC
  • EP3682325B1 patent drawingFigure 1
  • EP3682325B1 patent drawingFigure 2
  • EP3682325B1 patent drawingFigure 3

AI summary

Techniques for fine-grained firewall policy enforcement using session APP ID and endpoint process ID correlation are disclosed. In some embodiments, a system/process/computer program product for fine-grained firewall policy enforcement using session APP ID and endpoint process ID correlation includes receiving, at a network device on an enterprise network, process identification (ID) information from an endpoint (EP) agent executed on an EP device, in which the process identification information identifies a process that is initiating a network session from the EP device on the enterprise network; monitoring network communications associated with the network session at the network device to identify an application identification (APP ID) for the network session; and performing an action based on a security policy using the process ID information and the APP ID.