Flow Metadata Exchange Between SD-WAN and Security Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In SD-WAN environments, the inefficient use of computing resources and inconsistent security monitoring occur due to repeated and costly meta data determinations (e.g., App ID, User ID, Device ID, Content ID) at both SD-WAN devices and cloud-based security services, leading to scalability issues and gaps in security posture.
Innovation Solution
Implementing a system that exchanges flow meta data between network and security functions, where meta data is determined at one location and communicated to the other, reducing redundant computations and ensuring consistency, by encapsulating meta information in packet headers or using out-of-band communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If meta data determination is performed at both SD-WAN devices and cloud-based security services, then security monitoring coverage is improved, but computing resource consumption increases and scalability deteriorates
Solution Approach 1:
The patent combines the meta data determination function at both SD-WAN devices and cloud-based security services into a unified approach where the same meta data is generated once and shared between components, eliminating redundant computations while maintaining comprehensive security monitoring coverage
Solution Approach 2:
The patent performs meta data determination preliminarily at the SD-WAN device before traffic reaches the cloud-based security service, so that the security service can directly utilize the pre-determined meta data without performing redundant determination operations
2Reliability
If meta data determination is performed at both SD-WAN devices and cloud-based security services, then security monitoring coverage is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal meta data format and exchange mechanism that allows the same meta data structure to be used across SD-WAN devices and cloud-based security services, reducing system complexity while enabling comprehensive security monitoring through standardized multi-functional usage
3Productivity
If flow meta data is exchanged between network and security functions, then computing costs are reduced, but communication overhead increases
Solution Approach 1:
The patent extracts only the essential meta data elements needed for security monitoring and exchanges them between network and security functions, rather than transmitting complete flow data, thereby reducing communication overhead while maintaining computing efficiency benefits
Data Source
AI summary
Techniques for providing flow meta data exchanges between network and security functions for a security service are disclosed. In some embodiments, a system/process/computer program product for providing flow meta data exchanges between network and security functions for a security service includes receiving a flow at a network gateway of a security service from a software-defined wide area network (SD-WAN) device; inspecting the flow to determine meta information associated with the flow; and communicating the meta information associated with the flow to the SD-WAN device.


