Firewall Notification via Proxy-Injected Browser Frame

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewalls do not provide adequate feedback to end users when blocking access to content, leading to confusion between application-related errors, network connectivity issues, and firewall actions, lacking transparency in informing users about events or violations.

Innovation Solution

A method and system where a filtering device, such as a firewall, receives and evaluates requests from client applications, determines whether to block or allow them based on policies, and notifies users through a predefined message displayed within the application, providing information on blocked content, including reasons and categories, using a proxy-injected frame within a web browser or other applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall blocks requests based on policies, then network security is improved, but user feedback and transparency deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoiduser feedback
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a notification system that provides feedback to users when their requests are blocked by the firewall. The system captures blocked request information and displays it through various channels including in-application notifications, toolbar messages, and email alerts, ensuring users receive timely feedback about why their requests were denied while maintaining security policies.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary notification component that sits between the firewall and the user. This intermediary captures the firewall's blocking decisions and translates them into user-friendly notifications, mediating the communication between the security system and end users without compromising either security or user experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a firewall blocks requests without notification, then device complexity is reduced, but user confusion increases

Engineering Contradiction:
Improvefirewall systemVSAvoiduser understanding
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The notification system is designed to automatically generate and deliver notifications without requiring additional user action or system configuration. Once the firewall blocks a request, the system autonomously captures the event, formats the notification, and delivers it through appropriate channels, making the complexity management self-contained while improving user understanding.

Inventive Principle:
Principle #25Self-service

3Loss of information

If real-time notifications are provided to users, then user awareness is improved, but system resource consumption increases

Engineering Contradiction:
Improveuser awarenessVSAvoidsystem resources
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The notification system dynamically adjusts its behavior based on system conditions and user preferences. It can switch between synchronous real-time notifications and asynchronous delayed notifications, and can adjust notification frequency and channels based on system resource availability and user configuration, optimizing the balance between user awareness and resource consumption.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10742601B2Notifying users within a protected network regarding events and information
Publication Date: 2020.08.11 FORTINET INC
  • US10742601B2 patent drawing
  • US10742601B2 patent drawing
  • US10742601B2 patent drawing

AI summary

Systems and methods are provided for notifying users within a protected network about various events and information. According to one embodiment, a method includes receiving, by a filtering device, a request originated by an application running on a client device. The method further includes making a determination, by the filtering device, whether the request is to be blocked or allowed, based on the one or more policies. If the request is to be blocked, a notification is provided to a user of the client device regarding the determination by causing the application to display a predefined message.