Dynamic Firewall Pinhole Testing and Delay Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

VoIP networks face security challenges due to the lack of built-in security functions in IP networks, making it difficult to implement security enhancements like IPSec, and traditional firewalls are not practical for dynamic VoIP traffic, leading to vulnerabilities that can be exploited for Denial of Service Attacks or network takeover.

Innovation Solution

The development of a testing method and apparatus for firewalls that dynamically open and close ports, using Integrated Intelligent End Points (IIEPs) to verify compliance with design specifications, monitor port opening and closing delays, and detect excessive delays or vulnerabilities, with a time/spatial fault detector and root-cause analysis engine to ensure firewall security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls are used to block unwanted traffic, then network security is improved, but the dynamic nature of VoIP traffic cannot be accommodated

Engineering Contradiction:
Improvenetwork securityVSAvoiddynamic traffic accommodation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic pinhole filtering that allows firewalls to dynamically open and close ports based on call state. The firewall transitions from static port blocking to dynamic port control, opening specific ports only during active calls and closing them afterward, thereby accommodating the dynamic nature of VoIP traffic while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameters of the firewall by introducing time-based and state-based port control. Instead of fixed port rules, the firewall now dynamically adjusts port opening/closing based on call establishment and termination events, transforming the firewall behavior to match the dynamic characteristics of VoIP communications.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic pinhole filtering is implemented, then port security granularity is improved, but verification of correctness becomes difficult

Engineering Contradiction:
Improveport security granularityVSAvoidverification difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a feedback mechanism where the firewall reports its pinhole status and timing information back to a management system. This feedback loop enables continuous verification that the dynamic pinhole filtering is operating correctly by comparing actual behavior against expected security policies and timing requirements.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces manual verification methods with automated monitoring and analysis tools. Instead of relying on manual checking of firewall operations, the patent employs computational tools that automatically analyze firewall logs, timing data, and port state information to verify correctness and detect vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If strict verification of firewall operation is performed, then security is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification system is segmented into separate functional modules: a monitoring component that collects firewall operation data, an analysis component that processes and verifies the data against security policies, and a reporting component that presents results. This segmentation allows complex verification tasks to be divided into manageable functions, reducing overall system complexity while maintaining thorough verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary verification system that acts as a mediator between the firewall and the security management architecture. This intermediary layer handles the complexity of verification operations separately, allowing the firewall to focus on its primary function of traffic filtering while the verification system independently analyzes security compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If firewall port opening and closing delays are increased, then processing capacity is improved, but security vulnerability windows increase

Engineering Contradiction:
Improveprocessing capacityVSAvoidsecurity vulnerability windows
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system implements self-monitoring and self-regulation capabilities where the firewall tracks its own port opening and closing timing. When delays approach thresholds that create vulnerability windows, the system automatically adjusts processing parameters or alerts administrators, enabling the firewall to self-regulate the balance between processing capacity and security without external intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes pre-defined timing thresholds and buffer periods that anticipate potential vulnerability windows. By setting these parameters in advance based on security requirements, the system creates a cushion against excessive delays before they can result in actual security breaches, allowing operational flexibility while maintaining security margins.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS7886348B2Security management system for monitoring firewall operation
Publication Date: 2011.02.08 PALO ALTO NETWORKS INC
  • US7886348B2 patent drawing
  • US7886348B2 patent drawing
  • US7886348B2 patent drawing

AI summary

A test method for Internet-Protocol packet networks that verifies the proper functioning of a dynamic pinhole filtering implementation as well as quantifying network vulnerability statistically, as pinholes are opened and closed is described. Specific potential security vulnerabilities that may be addressed through testing include: 1) excessive delay in opening pinholes, resulting in an unintentional denial of service; 2) excessive delay in closing pinholes, creating a closing delay window of vulnerability; 3) measurement of the length of various windows of vulnerability; 4) setting a threshold on a window of vulnerability such that it triggers an alert when a predetermined value is exceeded; 5) determination of incorrectly allocated pinholes, resulting in a denial of service; 6) determining the opening of extraneous pinhole/IP address combinations through a firewall which increase the network vulnerability through unrecognized backdoors; and 7) determining the inability to correlate call state information with dynamically established rules in the firewall.