Firewall Session APP ID Correlation With Endpoint Process ID
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing advanced or next generation firewalls lack process/application information at the endpoint device, limiting their ability to implement fine-grained security policies and effectively detect and block sophisticated attack vectors, such as malware evasions and rootkits.
Innovation Solution
Techniques for correlating session application identification (APP ID) with endpoint process identification (EP process ID) to enhance firewall policy enforcement, using trusted agents on endpoints to monitor and communicate process information to the firewall, enabling fine-grained security policies and detecting abnormal network sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall policies are used without process ID correlation, then device complexity is reduced, but security reliability is insufficient due to inability to detect sophisticated attack vectors
Solution Approach 1:
The patent introduces an intermediary mechanism that correlates session APP ID with endpoint process ID to bridge the gap between network-level firewall filtering and application-level process control. This correlation layer enables sophisticated security policies without requiring complete redesign of the firewall architecture, thus improving reliability while controlling complexity
Solution Approach 2:
The patent segments the security enforcement into multiple layers: network-level APP ID filtering and endpoint-level process ID verification. This segmentation allows each layer to handle specific aspects of security, improving overall reliability while distributing complexity across different components rather than concentrating it in a single complex system
2Difficulty of detecting and measuring
If fine-grained security policies are implemented using process ID correlation, then security detection capability is improved, but computational overhead increases
Solution Approach 1:
The patent applies partial action by selectively correlating process IDs only for sessions that require fine-grained security inspection, rather than performing full process ID correlation on all network traffic. This selective approach enhances detection capability for suspicious traffic while minimizing unnecessary computational overhead on legitimate traffic
Solution Approach 2:
The patent performs preliminary action by establishing process ID correlation mechanisms in advance and maintaining cached process information at the endpoint. This preliminary setup enables faster real-time detection without requiring intensive computational resources during actual security inspection, thus improving detection capability while reducing ongoing computational overhead
3Reliability
If all network sessions are inspected for process ID correlation, then security monitoring is comprehensive, but processing time increases
Solution Approach 1:
The patent implements partial monitoring by focusing process ID correlation and security inspection efforts on sessions that exhibit suspicious characteristics or match known attack patterns, rather than uniformly inspecting all sessions. This approach maintains comprehensive security monitoring for critical threats while reducing processing time for routine traffic
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques for fine-grained firewall policy enforcement using session APP ID and endpoint process ID correlation are disclosed. In some embodiments, a system/process/computer program product for fine-grained firewall policy enforcement using session APP ID and endpoint process ID correlation includes receiving, at a network device on an enterprise network, process identification (ID) information from an endpoint (EP) agent executed on an EP device, in which the process identification information identifies a process that is initiating a network session from the EP device on the enterprise network; monitoring network communications associated with the network session at the network device to identify an application identification (APP ID) for the network session; and performing an action based on a security policy using the process ID information and the APP ID.