Flow Metadata Exchange Between SD-WAN and Security Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In SD-WAN environments, the inefficient use of computing resources and inconsistent security monitoring occur due to repeated and costly meta data determinations (e.g., App ID, User ID, Device ID, Content ID) at both SD-WAN devices and cloud-based security services, leading to scalability issues and gaps in security posture.

Innovation Solution

Implementing a system that exchanges flow meta data between network and security functions, where meta data is determined at one location and communicated to the other, reducing redundant computations and ensuring consistency, by encapsulating meta information in packet headers or using out-of-band communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If meta data determination is performed at both SD-WAN devices and cloud-based security services, then security monitoring coverage is improved, but computing resource consumption increases and scalability deteriorates

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidcomputing resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines the meta data determination function at both SD-WAN devices and cloud-based security services into a unified approach where the same meta data is generated once and shared between components, eliminating redundant computations while maintaining comprehensive security monitoring coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs meta data determination preliminarily at the SD-WAN device before traffic reaches the cloud-based security service, so that the security service can directly utilize the pre-determined meta data without performing redundant determination operations

Inventive Principle:
Principle #10Preliminary action

2Reliability

If meta data determination is performed at both SD-WAN devices and cloud-based security services, then security monitoring coverage is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal meta data format and exchange mechanism that allows the same meta data structure to be used across SD-WAN devices and cloud-based security services, reducing system complexity while enabling comprehensive security monitoring through standardized multi-functional usage

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If flow meta data is exchanged between network and security functions, then computing costs are reduced, but communication overhead increases

Engineering Contradiction:
Improvecomputing efficiencyVSAvoidcommunication data volume
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential meta data elements needed for security monitoring and exchanges them between network and security functions, rather than transmitting complete flow data, thereby reducing communication overhead while maintaining computing efficiency benefits

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11750563B2Flow metadata exchanges between network and security functions for a security service
Publication Date: 2023.09.05 PALO ALTO NETWORKS INC
  • US11750563B2 patent drawing
  • US11750563B2 patent drawing
  • US11750563B2 patent drawing

AI summary

Techniques for providing flow meta data exchanges between network and security functions for a security service are disclosed. In some embodiments, a system/process/computer program product for providing flow meta data exchanges between network and security functions for a security service includes receiving a flow at a network gateway of a security service from a software-defined wide area network (SD-WAN) device; inspecting the flow to determine meta information associated with the flow; and communicating the meta information associated with the flow to the SD-WAN device.