Stateful Firewall CPU Optimization via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security technologies for VoIP networks face challenges in scalability and performance, particularly in stateful firewall implementations, which are CPU-intensive and struggle to maintain compliance with various signaling scenarios and loading conditions, leading to potential vulnerabilities and performance degradation.

Innovation Solution

The development of methods and apparatus for benchmarking and verifying the performance of firewall security devices, including the use of Intelligent Integrated End Points (IIEPs) and Integrated Testing Analyzers, to evaluate dynamic pinhole filtering capabilities under carrier-class conditions, ensuring compliance with full protocol stacks and identifying vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If stateful firewall capabilities are implemented for VoIP security protection, then security is improved, but CPU utilization increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidCPU utilization
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the stateful firewall functionality into separate processing stages: state table management is handled by one processor while packet filtering and inspection are handled by another processor. This segmentation allows the CPU-intensive state table operations to be isolated from the real-time packet processing, reducing the overall CPU utilization burden on the firewall device while maintaining security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a state table as an intermediary data structure that pre-stores connection state information. Instead of performing complex stateful inspection for every packet, the system uses the state table as a mediator to quickly determine whether to allow or block packets based on pre-established connection states, significantly reducing real-time CPU processing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dynamic pinhole filtering is implemented to protect against attacks, then security is improved, but performance degradation occurs

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-establishing state table entries for authorized connections before actual data transmission occurs. When a connection is initially authorized, the state table is populated with the necessary filtering rules in advance. This allows subsequent packets to be processed quickly through simple table lookups rather than complex real-time analysis, maintaining high performance while providing dynamic pinhole filtering protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of packet processing from complex stateful inspection to simplified state table lookup. By transforming the processing mechanism based on the connection state, the system achieves fast performance for authorized traffic while maintaining security through the state table's authorization controls.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If protocol compliance verification is performed under all signaling scenarios, then reliability is improved, but testing complexity increases

Engineering Contradiction:
Improveprotocol complianceVSAvoidtesting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial action by focusing verification testing on the most critical and common signaling scenarios rather than exhaustively testing all possible edge cases. The testing framework prioritizes scenarios that are most likely to expose vulnerabilities or non-compliance issues, providing sufficient reliability verification without the complexity of comprehensive exhaustive testing.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements feedback mechanisms where test results from signaling scenario verification are fed back into the testing framework to automatically adjust and prioritize subsequent testing. This feedback loop allows the system to learn from previous test outcomes and focus resources on areas that need the most attention, reducing overall testing complexity while maintaining high reliability verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7886350B2Methodology for measurements and analysis of protocol conformance, performance and scalability of stateful border gateways
Publication Date: 2011.02.08 PALO ALTO NETWORKS INC
  • US7886350B2 patent drawing
  • US7886350B2 patent drawing
  • US7886350B2 patent drawing

AI summary

Testing of Internet-Protocol packet network perimeter protection devices, e.g., Border Gateways such as Session Border Controllers, including dynamic pinhole capable firewalls are discussed. Analysis and testing of these network perimeter protection devices is performed to evaluate the ability of such device to perform at carrier class levels while being subjected to many different protocol test cases. The efficiency of state look table functions as well as call signaling processing capacity, implemented in a particular perimeter protection device, are determined and evaluated. Proper performance and efficiency of such perimeter protection devices are evaluated as a function of: incoming call rate, total pre-existing active calls, and different protocol test cases. Various different network perimeter protection devices, e.g., of different types and/or from different manufactures, can be benchmarked for degree of protocol stack implementation/suitability to carrier class environments and comparatively evaluated. Test equipment devices, e.g., Integrated Intelligent End Points (IIEPs), for fault testing, evaluating and stressing the network perimeter protection devices in a system environment are described. Typically these specialized test devices are used in pairs, one on each side of the firewall under test. These test equipment devices include a traffic generator module, a protocol compliance testing module, monitoring and analysis capability including a CPU utilization analysis module, a protocol analysis module, and a graphical output capability.