Firewall Lateral Traffic Punting via Process Risk Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing advanced or next-generation firewalls lack the capability for fine-grained security policy enforcement using session application identification (APP ID) and endpoint process identification (EP process ID) correlation, which is essential for restricting network traffic based on authorized processes and resources, thereby failing to effectively detect and prevent advanced threats like malware and rootkits.

Innovation Solution

Implementing techniques for fine-grained firewall policy enforcement by correlating network sessions with endpoint process information, using trusted agents to identify and notify the firewall of process IDs, and applying security policies based on APP ID and process ID information, including hierarchical process groupings and secure communication methods to facilitate enhanced security analysis and telemetry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If firewalls filter traffic using basic rules and policies, then network security is provided, but fine-grained control over network traffic based on process identification is lacking

Engineering Contradiction:
Improvetraffic control granularityVSAvoidfirewall policy complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The firewall policy is segmented into multiple layers: basic traffic filtering rules and fine-grained process-specific rules. The system divides network traffic control into coarse-grained (application-level) and fine-grained (process-level) segments, allowing administrators to apply different levels of control based on security requirements without overwhelming complexity throughout the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Fine-grained process identification and control are applied locally only to specific traffic flows that require enhanced security, rather than applying complex process-level filtering to all traffic. The firewall dynamically determines which traffic streams need process-level inspection based on security policies, applying detailed control only where necessary.

Inventive Principle:
Principle #3Local quality

2Reliability

If firewalls inspect all network traffic in detail, then security detection capability is improved, but processing performance and throughput deteriorate

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The firewall performs detailed process identification and inspection on only a subset of traffic that matches security policies requiring fine-grained control, rather than inspecting all traffic at the same level. This partial action approach maintains high throughput for standard traffic while providing enhanced detection where needed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system maintains continuous network traffic flow through the firewall without interruption, using efficient process identification methods that do not block traffic. Process ID extraction and correlation operations are performed in a manner that allows traffic to continue flowing while security analysis proceeds concurrently.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If firewalls correlate APP ID with endpoint process ID, then security policy enforcement is improved, but implementation complexity increases

Engineering Contradiction:
Improvepolicy enforcement accuracyVSAvoidcorrelation mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses an intermediary correlation mechanism that matches APP IDs observed at the firewall with process IDs from endpoint agents or process information from packet payloads. This intermediary layer translates between different identification systems without requiring direct complex integration between firewall and endpoint security software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces complex mechanical correlation systems with information-based approaches, using process ID strings extracted from network traffic or endpoint reports to correlate with APP IDs. This substitution uses data processing rather than complex hardware or mechanical synchronization mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12003485B2Outbound/inbound lateral traffic punting based on process risk
Publication Date: 2024.06.04 PALO ALTO NETWORKS INC
  • US12003485B2 patent drawing
  • US12003485B2 patent drawing
  • US12003485B2 patent drawing

AI summary

Techniques for outbound/inbound lateral traffic punting based upon process risk are disclosed. In some embodiments, a system/process/computer program product for outbound/inbound lateral traffic punting based upon process risk includes receiving, at a network device on an enterprise network, process identification (ID) information from an endpoint (EP) agent executed on an EP device, in which the process ID information identifies a process that is associated with an outbound or inbound network session on the EP device on the enterprise network, and the EP agent selected the network session for punting to the network device for inspection; monitoring network communications associated with the network session at the network device to identify an application identification (APP ID) for the network session; and performing an action based on a security policy using the process ID information and the APP ID.