Host Firewall Edge Traversal Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing host firewalls are unable to securely manage unsolicited traffic due to their IP-version agnosticism and lack of awareness about edge traversal technologies, leading to potential security risks as they inadvertently allow unsolicited traffic from outside the network via edge traversal services.
Innovation Solution
Implementing an edge traversal parameter in host firewall rules that allows or blocks unsolicited traffic based on whether it has traversed the network edge, ensuring that traffic matching the edge traversal criterion is allowed while traffic failing to satisfy the criterion is blocked.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If host firewall rules allow unsolicited traffic to applications or services, then legitimate inbound traffic can reach the host, but the host becomes exposed to unsolicited traffic from outside the network via edge traversal services
Solution Approach 1:
The patent applies local quality by creating distinct interface types with different security characteristics. The edge traversal interface is differentiated from other network interfaces, allowing the firewall to apply specific security rules tailored to each interface type. This enables the system to allow unsolicited traffic on the edge traversal interface while blocking it on other interfaces, resolving the contradiction between receiving legitimate traffic and preventing security exposure.
Solution Approach 2:
The patent segments the network interface into different types, specifically identifying an edge traversal interface versus other interfaces. By segmenting the interface classification, the firewall can apply granular rules that evaluate whether incoming traffic arrived via edge traversal, enabling selective permission of unsolicited traffic based on the arrival path rather than applying blanket rules to all interfaces.
2Device complexity
If existing IP-version agnostic firewall rules are used, then firewall rules can be simplified and applied universally, but they cannot distinguish between traffic from network edge and other sources
Solution Approach 1:
The patent adds a new dimension to firewall rule evaluation by introducing an interface type criterion. Instead of only evaluating traditional firewall parameters like IP address, port, and protocol, the system now evaluates the type of network interface through which traffic arrived. This additional dimension enables precise identification of edge traversal traffic without complicating the fundamental firewall rule structure, as the interface type is automatically determined by the system.
3Adaptability or versatility
If edge traversal service is enabled for a host, then unsolicited inbound traffic can traverse through the NAT or firewall edge device, but the host becomes vulnerable to security risks from external traffic
Solution Approach 1:
The patent applies local quality by creating distinct interface types with different security characteristics. The edge traversal interface is differentiated from other network interfaces, allowing the firewall to apply specific security rules tailored to each interface type. This enables the system to allow unsolicited traffic on the edge traversal interface while blocking it on other interfaces, resolving the contradiction between receiving legitimate traffic and preventing security exposure.
Solution Approach 2:
The patent introduces an intermediary evaluation step in the firewall rule processing. Before allowing unsolicited traffic to reach the host, the system evaluates whether the traffic arrived via an edge traversal interface by checking the interface type criterion. This intermediary check acts as a mediator that permits legitimate edge traversal traffic while blocking malicious external traffic, thereby maintaining reliability while preserving adaptability.
Data Source
AI summary
A host firewall can determine and consider whether unsolicited traffic is inbound from beyond the edge of the network and allow or block such traffic based at least in part upon this characteristic. In one implementation, an edge traversal parameter can be set on a host firewall rule, which typically includes other parameters such as port, protocol, etc. If the unsolicited traffic received via an edge traversal interface matches a host firewall rule that has the edge traversal criterion, then the firewall does not block the traffic. On the other hand, if the unsolicited traffic received via an edge traversal interface fails to satisfy the edge traversal criterion on any firewall rule, then the firewall blocks the traffic.


