Host Firewall Edge Traversal Traffic Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing host firewalls are unable to securely manage unsolicited traffic due to their IP-version agnosticism and lack of awareness about edge traversal technologies, leading to potential security risks as they inadvertently allow unsolicited traffic from outside the network via edge traversal services.

Innovation Solution

Implementing an edge traversal parameter in host firewall rules that allows or blocks unsolicited traffic based on whether it has traversed the network edge, ensuring that traffic matching the edge traversal criterion is allowed while traffic failing to satisfy the criterion is blocked.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If host firewall rules allow unsolicited traffic to applications or services, then legitimate inbound traffic can reach the host, but the host becomes exposed to unsolicited traffic from outside the network via edge traversal services

Engineering Contradiction:
Improveability to receive unsolicited trafficVSAvoidsecurity exposure to unsolicited traffic
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by creating distinct interface types with different security characteristics. The edge traversal interface is differentiated from other network interfaces, allowing the firewall to apply specific security rules tailored to each interface type. This enables the system to allow unsolicited traffic on the edge traversal interface while blocking it on other interfaces, resolving the contradiction between receiving legitimate traffic and preventing security exposure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the network interface into different types, specifically identifying an edge traversal interface versus other interfaces. By segmenting the interface classification, the firewall can apply granular rules that evaluate whether incoming traffic arrived via edge traversal, enabling selective permission of unsolicited traffic based on the arrival path rather than applying blanket rules to all interfaces.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If existing IP-version agnostic firewall rules are used, then firewall rules can be simplified and applied universally, but they cannot distinguish between traffic from network edge and other sources

Engineering Contradiction:
Improvefirewall rule simplicityVSAvoidability to identify traffic origin
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent adds a new dimension to firewall rule evaluation by introducing an interface type criterion. Instead of only evaluating traditional firewall parameters like IP address, port, and protocol, the system now evaluates the type of network interface through which traffic arrived. This additional dimension enables precise identification of edge traversal traffic without complicating the fundamental firewall rule structure, as the interface type is automatically determined by the system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If edge traversal service is enabled for a host, then unsolicited inbound traffic can traverse through the NAT or firewall edge device, but the host becomes vulnerable to security risks from external traffic

Engineering Contradiction:
Improveability to receive inbound trafficVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by creating distinct interface types with different security characteristics. The edge traversal interface is differentiated from other network interfaces, allowing the firewall to apply specific security rules tailored to each interface type. This enables the system to allow unsolicited traffic on the edge traversal interface while blocking it on other interfaces, resolving the contradiction between receiving legitimate traffic and preventing security exposure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary evaluation step in the firewall rule processing. Before allowing unsolicited traffic to reach the host, the system evaluates whether the traffic arrived via an edge traversal interface by checking the interface type criterion. This intermediary check acts as a mediator that permits legitimate edge traversal traffic while blocking malicious external traffic, thereby maintaining reliability while preserving adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8370919B2Host firewall integration with edge traversal technology
Publication Date: 2013.02.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8370919B2 patent drawing
  • US8370919B2 patent drawing
  • US8370919B2 patent drawing

AI summary

A host firewall can determine and consider whether unsolicited traffic is inbound from beyond the edge of the network and allow or block such traffic based at least in part upon this characteristic. In one implementation, an edge traversal parameter can be set on a host firewall rule, which typically includes other parameters such as port, protocol, etc. If the unsolicited traffic received via an edge traversal interface matches a host firewall rule that has the edge traversal criterion, then the firewall does not block the traffic. On the other hand, if the unsolicited traffic received via an edge traversal interface fails to satisfy the edge traversal criterion on any firewall rule, then the firewall blocks the traffic.