Firewall Verification Unit for Application Layer Message Conformity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Standard firewalls are limited in their ability to provide comprehensive security for the application layer of communication models, primarily relying on pattern or signature recognition, which does not adequately address the security needs of critical applications.
Innovation Solution
A firewall system that includes a verification unit for comparing messages with reference data to detect conformity, generating alert signals for non-conforming messages, and an alert signal management device to implement protective actions, specifically designed to control messages at the application layer of the OSI model.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard firewalls use pattern or signature recognition for application layer security, then device complexity is reduced and ease of operation is improved, but security reliability is insufficient for critical applications
Solution Approach 1:
The patent applies preliminary action by pre-defining reference data including predetermined messages and permitted values for fields before message verification occurs. The verification unit compares incoming messages against these pre-established reference data, allowing the system to perform comprehensive security checks without adding complexity to the real-time verification process. This preparation of reference data in advance enables reliable security verification while maintaining operational simplicity.
2Reliability
If firewalls perform comprehensive message content analysis for application layer security, then security reliability is improved, but processing speed and productivity decrease
Solution Approach 1:
The patent segments the message verification process into distinct components: the verification unit handles the actual message content comparison, while the central unit manages alert signal generation. This segmentation allows the verification unit to focus efficiently on comparing messages against reference data, improving processing speed while maintaining comprehensive security analysis through the coordinated operation of specialized units.
Solution Approach 2:
The patent implements feedback through the alert signal mechanism. When the verification unit detects a lack of conformity between a message and reference data, it triggers an alert signal generated by the central unit. This feedback loop enables the system to quickly identify and respond to security issues without requiring continuous comprehensive analysis of every message, thus improving processing efficiency while maintaining security reliability.
3Reliability
If firewalls monitor all messages between communication elements, then security coverage is improved, but loss of time for message processing increases
Solution Approach 1:
The patent applies partial action by having the verification unit recognize and compare only specific messages that match predetermined patterns in the reference data. Rather than performing exhaustive analysis on every single message, the system focuses verification efforts on messages that require security checking based on their recognition against reference data. This selective approach maintains comprehensive security coverage for relevant messages while reducing unnecessary processing time for other messages.
Data Source
AI summary
A firewall includes a verification unit for comparing messages transiting between the two communication elements with data, called reference data, contained in a database and for detecting, where applicable, a lack of conformity of a message in transit with respect to the reference data. The reference data includes predetermined messages and at least authorized values for fields of the predetermined messages. A central unit for generates an alert signal in the event of the verification unit detecting a lack of conformity of a message in transit. A transmission interface is configured to transmit any alert signal to at least one alert signal management device, which will generate an appropriate protective action when an alert signal is generated.

