Host-Initiated Firewall Discovery via Metadata Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies are inadequate in detecting and managing botnets and malicious software that exploit vulnerabilities and use encryption, leading to difficulties in identifying and preventing unauthorized network activities, especially when they masquerade as normal traffic or use encryption protocols.

Innovation Solution

A host-initiated system and method for discovering and managing firewalls through a firewall cache and metadata sharing, where a firewall agent intercepts network flows, sends discovery queries, and correlates metadata with network policies to identify and manage routes, using protocols like ICMP and UDP for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current network security technologies are used to detect and manage botnets, then basic network traffic monitoring is performed, but malicious activities masquerading as normal traffic or using encryption cannot be effectively detected

Engineering Contradiction:
Improvedetection accuracyVSAvoidmalicious activity identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a firewall as an intermediary component between the host and the network. The firewall intercepts network flows before they leave or enter the host, allowing security policies to be applied to the actual data traffic rather than just metadata. This intermediary position enables the firewall to detect and block malicious activities even when they masquerade as normal traffic or use encryption, directly resolving the detection accuracy problem.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by intercepting and inspecting network flows before they are transmitted or received. The firewall agent on the host captures outgoing flows and incoming flows, applying security policies in advance before the traffic reaches the network or enters the host. This preliminary inspection enables detection of malicious activities before they can execute or spread, improving reliability while maintaining low overhead.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If firewall discovery and metadata sharing is implemented, then granular control of traffic and route management is achieved, but system complexity increases

Engineering Contradiction:
Improvetraffic control granularityVSAvoidfirewall discovery mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The firewall discovery mechanism operates in a self-service manner where the host automatically discovers its dedicated firewall through standardized protocols (ICMP or UDP) without requiring manual configuration. The firewall agent on the host sends discovery queries and automatically receives responses identifying the firewall's network address. This self-service approach enables granular traffic control and route management while minimizing system complexity through automation and standardization.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a universal firewall discovery mechanism that works across different network configurations and protocols. The same discovery process using standardized ICMP or UDP protocols can identify firewalls in various network topologies, whether the host has a single firewall or multiple firewalls for different routes. This multi-functionality achieves versatile traffic control without increasing device complexity, as the mechanism adapts to different scenarios using the same core approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If network flows are intercepted and metadata is correlated with network policies, then effective route management is achieved, but protocol overhead increases

Engineering Contradiction:
Improveroute management efficiencyVSAvoidprotocol overhead
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent extracts only the essential metadata from intercepted network flows that is necessary for route management and policy application. Rather than processing entire packet contents, the firewall agent extracts key metadata elements such as source/destination addresses, ports, and protocol information. This extraction approach enables effective route management by correlating minimal necessary metadata with network policies, thereby achieving productivity improvements while minimizing protocol overhead and energy loss.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8800024B2System and method for host-initiated firewall discovery in a network environment
Publication Date: 2014.08.05 MCAFEE LLC
  • US8800024B2 patent drawing
  • US8800024B2 patent drawing
  • US8800024B2 patent drawing

AI summary

A method is provided in one example embodiment that includes intercepting a network flow to a destination node having a network address and sending a discovery query based on a discovery action associated with the network address in a firewall cache. A discovery result may be received and metadata associated with the flow may be sent to a firewall before releasing the network flow. In other embodiments, a discovery query may be received from a source node and a discovery result sent to the source node, wherein the discovery result identifies a firewall for managing a route to a destination node. Metadata may be received from the source node over a metadata channel. A network flow from the source node to the destination node may be intercepted, and the metadata may be correlated with the network flow to apply a network policy to the network flow.