Firewall Lateral Traffic Punting via Process Risk Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing advanced or next-generation firewalls lack the capability for fine-grained security policy enforcement using session application identification (APP ID) and endpoint process identification (EP process ID) correlation, which is essential for restricting network traffic based on authorized processes and resources, thereby failing to effectively detect and prevent advanced threats like malware and rootkits.
Innovation Solution
Implementing techniques for fine-grained firewall policy enforcement by correlating network sessions with endpoint process information, using trusted agents to identify and notify the firewall of process IDs, and applying security policies based on APP ID and process ID information, including hierarchical process groupings and secure communication methods to facilitate enhanced security analysis and telemetry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If firewalls filter traffic using basic rules and policies, then network security is provided, but fine-grained control over network traffic based on process identification is lacking
Solution Approach 1:
The firewall policy is segmented into multiple layers: basic traffic filtering rules and fine-grained process-specific rules. The system divides network traffic control into coarse-grained (application-level) and fine-grained (process-level) segments, allowing administrators to apply different levels of control based on security requirements without overwhelming complexity throughout the entire system.
Solution Approach 2:
Fine-grained process identification and control are applied locally only to specific traffic flows that require enhanced security, rather than applying complex process-level filtering to all traffic. The firewall dynamically determines which traffic streams need process-level inspection based on security policies, applying detailed control only where necessary.
2Reliability
If firewalls inspect all network traffic in detail, then security detection capability is improved, but processing performance and throughput deteriorate
Solution Approach 1:
The firewall performs detailed process identification and inspection on only a subset of traffic that matches security policies requiring fine-grained control, rather than inspecting all traffic at the same level. This partial action approach maintains high throughput for standard traffic while providing enhanced detection where needed.
Solution Approach 2:
The system maintains continuous network traffic flow through the firewall without interruption, using efficient process identification methods that do not block traffic. Process ID extraction and correlation operations are performed in a manner that allows traffic to continue flowing while security analysis proceeds concurrently.
3Reliability
If firewalls correlate APP ID with endpoint process ID, then security policy enforcement is improved, but implementation complexity increases
Solution Approach 1:
The system uses an intermediary correlation mechanism that matches APP IDs observed at the firewall with process IDs from endpoint agents or process information from packet payloads. This intermediary layer translates between different identification systems without requiring direct complex integration between firewall and endpoint security software.
Solution Approach 2:
The patent replaces complex mechanical correlation systems with information-based approaches, using process ID strings extracted from network traffic or endpoint reports to correlate with APP IDs. This substitution uses data processing rather than complex hardware or mechanical synchronization mechanisms.
Data Source
AI summary
Techniques for outbound/inbound lateral traffic punting based upon process risk are disclosed. In some embodiments, a system/process/computer program product for outbound/inbound lateral traffic punting based upon process risk includes receiving, at a network device on an enterprise network, process identification (ID) information from an endpoint (EP) agent executed on an EP device, in which the process ID information identifies a process that is associated with an outbound or inbound network session on the EP device on the enterprise network, and the EP agent selected the network session for punting to the network device for inspection; monitoring network communications associated with the network session at the network device to identify an application identification (APP ID) for the network session; and performing an action based on a security policy using the process ID information and the APP ID.


