Firewall Data Flow Forwarding via Dynamic Health State Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewall policies lack a data flow health assessment, making it difficult to identify network attacks or abnormal activities and increasing administration costs due to the constant creation of new roles based on evolving user security states.

Innovation Solution

A data flow forwarding method and device that acquire a second health state of a data flow based on identifying information, using a health assessment database to determine access rights and employing firewall policy property sets that include the health state to decide whether to forward the data flow, thereby integrating a health assessment into the firewall policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If firewall policies constantly create new roles based on evolving user security states, then the system can adapt to different security conditions, but the administration cost and system complexity increase significantly

Engineering Contradiction:
Improveadaptability to security statesVSAvoidadministration cost
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter basis for firewall policies from static user roles to dynamic health states. Instead of creating new roles for different security conditions, the system uses health state parameters (derived from identifying information) to dynamically adjust access rights. This allows the firewall to adapt to evolving security states by parameter adjustment rather than role proliferation, reducing administration complexity while maintaining adaptability.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If firewall policies use multiple identifying information to determine access rights, then the control precision improves, but the difficulty of detecting and measuring increases

Engineering Contradiction:
Improveaccess right control precisionVSAvoidhealth state assessment difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by pre-establishing a health assessment database that stores the relationships between identifying information and health states. Before actual firewall policy enforcement, the system pre-processes and stores the assessment rules, so that during runtime, the firewall can quickly query and apply pre-computed health states without performing complex real-time analysis. This reduces the detection and measurement difficulty while maintaining precise access control based on multiple identifying information.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the firewall lacks health assessment capability, then the system simplicity is maintained, but the ability to identify network attacks or abnormal activities deteriorates

Engineering Contradiction:
Improveattack identification abilityVSAvoidfirewall policy structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a health assessment database as an intermediary between the firewall policy and the actual data flow filtering. The database stores pre-computed health states based on multiple identifying information, acting as a mediator that translates complex security assessments into simple health state parameters. This allows the firewall to gain attack identification capability through the intermediary database without significantly complicating the firewall's own policy structure, as the firewall simply queries and applies health states from the database.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9954898B2Data flow forwarding method and device
Publication Date: 2018.04.24 HILLSTONE NETWORKS CORP
  • US9954898B2 patent drawing
  • US9954898B2 patent drawing
  • US9954898B2 patent drawing

AI summary

This disclosure makes public a data flow forwarding method and device, and in this method, a second health state is acquired based on the first health state of one or more pieces of identifying information of the received data flow, wherein the first health state and second health state are associated with the access rights of the user and/or user device that sent the data flow; it employs firewall policy property sets to determine whether or not to forward the data flow, wherein the firewall policy property sets comprise: the second health state. The technical schemes based on this disclosure improve the ability of a firewall to identify network attacks or abnormal activities and reduce administration costs.