Firewall Security List Offload with Exponential Timeout

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-layer firewall systems are resource-intensive due to the high resource usage required by the final layers for security, leading to increased costs and inefficiencies in data packet analysis.

Innovation Solution

Implementing a system where a second layer of the firewall can apply a rule at a lower layer to block data packets based on previous interactions, reducing the need for resource-intensive analysis by higher layers, and using exponential timeout values to manage these rules dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-layer firewall security is implemented, then security level is improved, but resource usage increases

Engineering Contradiction:
Improvesecurity levelVSAvoidresource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by having lower firewall layers perform initial packet filtering and establish security rules before packets reach higher layers. The lower layers pre-process packets, apply basic security rules, and only pass genuinely suspicious packets to higher layers, thereby reducing the resource burden on multi-layer security systems while maintaining comprehensive security coverage

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the firewall system into multiple layers with distinct functions, where each layer handles specific types of security checks. Lower layers handle basic filtering and rule application, while higher layers focus on complex analysis. This segmentation allows the system to distribute resource usage across layers rather than concentrating all resource-intensive operations in a single layer

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If final layers perform resource-intensive analysis, then detection precision is improved, but productivity decreases

Engineering Contradiction:
Improvedetection precisionVSAvoidpacket processing throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial action by having lower firewall layers perform sufficient filtering and rule application to handle the majority of packets without involving higher layers. Only packets that partially match suspicious patterns or fail lower-layer checks are passed to higher layers for more intensive analysis. This partial processing approach maintains detection precision for suspicious packets while preserving overall system productivity

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10284521B2Automatic security list offload with exponential timeout
Publication Date: 2019.05.07 CISCO TECHNOLOGY INC
  • US10284521B2 patent drawing
  • US10284521B2 patent drawing
  • US10284521B2 patent drawing

AI summary

Disclosed are systems, methods, and computer-readable storage media for automatic security list offload with exponential timeout. A second layer of a firewall can determine that a first data, that previously passed through a first layer of the firewall, should be blocked. The second layer of the firewall can utilize more resources than the first layer of the firewall to determine whether to block a data packet. In response, a first rule can be applied at the first layer of the firewall to block data packets received from a source of the first data packet. Accordingly, a second data packet received from the source of the first data packet will be blocked at the first layer of the firewall based on the first rule.