Four Dimensional Network Session Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewall systems are ineffective in automatically defining and enforcing network sessions, as they rely on manual configuration and are prone to being bypassed by hackers, leading to outdated security measures.

Innovation Solution

Implementing a system that automatically defines and enforces network sessions based on four dimensions of segmentation (source, destination, port, and protocol) using a processing resource to monitor and classify network traffic, allowing for dynamic policy updates and enforcement without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual firewall configuration is used to block prohibited URLs, then security control is implemented, but the system becomes outdated easily and is prone to being bypassed by hackers

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidability to adapt to new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs self-service by automatically monitoring network traffic, extracting four-dimensional session definitions, classifying them as prohibited or allowed, and dynamically updating firewall rules without manual intervention. This automated self-updating mechanism ensures the security system remains current with evolving threats while maintaining reliable security control.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If manual firewall rules are configured for each URL, then explicit control is achieved, but the device complexity and maintenance burden increase

Engineering Contradiction:
Improvecontrol precisionVSAvoidconfiguration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Instead of manually configuring individual firewall rules for each URL, the system creates copies of four-dimensional session definitions from monitored network traffic. These session definition copies are automatically classified and used to generate firewall rules, dramatically reducing configuration complexity while maintaining precise control over network access.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system implements a universal classification mechanism that handles multiple types of network traffic and session definitions through a single automated process. The four-dimensional session definition structure (source IP, destination IP, source port, destination port) serves as a universal template that can represent any network connection, eliminating the need for separate manual configurations for different URL types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If dynamic firewall decisions are made for unclassified URLs, then flexibility is improved, but the system becomes prone to security gaps

Engineering Contradiction:
Improvedynamic decision makingVSAvoidsecurity consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements feedback by continuously monitoring network traffic, classifying observed sessions, and using these classifications to update firewall rules. This closed-loop feedback mechanism ensures that dynamic decisions are based on actual observed traffic patterns rather than static pre-configured rules, improving both flexibility and security consistency simultaneously.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11909826B1Systems and methods for four dimensional network session authorization
Publication Date: 2024.02.20 FORTINET INC
  • US11909826B1 patent drawing
  • US11909826B1 patent drawing
  • US11909826B1 patent drawing

AI summary

Various embodiments provide systems and methods for automatically defining and enforcing network sessions based upon at least four dimensions of segmentation.