Host-Initiated Firewall Discovery via Metadata Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security technologies are inadequate in detecting and managing botnets and malicious software that exploit vulnerabilities and use encryption, leading to difficulties in identifying and preventing unauthorized network activities, especially when they masquerade as normal traffic or use encryption protocols.
Innovation Solution
A host-initiated system and method for discovering and managing firewalls through a firewall cache and metadata sharing, where a firewall agent intercepts network flows, sends discovery queries, and correlates metadata with network policies to identify and manage routes, using protocols like ICMP and UDP for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current network security technologies are used to detect and manage botnets, then basic network traffic monitoring is performed, but malicious activities masquerading as normal traffic or using encryption cannot be effectively detected
Solution Approach 1:
The patent introduces a firewall as an intermediary component between the host and the network. The firewall intercepts network flows before they leave or enter the host, allowing security policies to be applied to the actual data traffic rather than just metadata. This intermediary position enables the firewall to detect and block malicious activities even when they masquerade as normal traffic or use encryption, directly resolving the detection accuracy problem.
Solution Approach 2:
The system performs preliminary actions by intercepting and inspecting network flows before they are transmitted or received. The firewall agent on the host captures outgoing flows and incoming flows, applying security policies in advance before the traffic reaches the network or enters the host. This preliminary inspection enables detection of malicious activities before they can execute or spread, improving reliability while maintaining low overhead.
2Adaptability or versatility
If firewall discovery and metadata sharing is implemented, then granular control of traffic and route management is achieved, but system complexity increases
Solution Approach 1:
The firewall discovery mechanism operates in a self-service manner where the host automatically discovers its dedicated firewall through standardized protocols (ICMP or UDP) without requiring manual configuration. The firewall agent on the host sends discovery queries and automatically receives responses identifying the firewall's network address. This self-service approach enables granular traffic control and route management while minimizing system complexity through automation and standardization.
Solution Approach 2:
The patent implements a universal firewall discovery mechanism that works across different network configurations and protocols. The same discovery process using standardized ICMP or UDP protocols can identify firewalls in various network topologies, whether the host has a single firewall or multiple firewalls for different routes. This multi-functionality achieves versatile traffic control without increasing device complexity, as the mechanism adapts to different scenarios using the same core approach.
3Productivity
If network flows are intercepted and metadata is correlated with network policies, then effective route management is achieved, but protocol overhead increases
Solution Approach 1:
The patent extracts only the essential metadata from intercepted network flows that is necessary for route management and policy application. Rather than processing entire packet contents, the firewall agent extracts key metadata elements such as source/destination addresses, ports, and protocol information. This extraction approach enables effective route management by correlating minimal necessary metadata with network policies, thereby achieving productivity improvements while minimizing protocol overhead and energy loss.
Data Source
AI summary
A method is provided in one example embodiment that includes intercepting a network flow to a destination node having a network address and sending a discovery query based on a discovery action associated with the network address in a firewall cache. A discovery result may be received and metadata associated with the flow may be sent to a firewall before releasing the network flow. In other embodiments, a discovery query may be received from a source node and a discovery result sent to the source node, wherein the discovery result identifies a firewall for managing a route to a destination node. Metadata may be received from the source node over a metadata channel. A network flow from the source node to the destination node may be intercepted, and the metadata may be correlated with the network flow to apply a network policy to the network flow.


