Hybrid WAF Proxy for Container Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web applications in container-based environments cannot be protected using traditional Web Application Firewalls (WAFs) as they cannot be directly accessed through IP addresses or Fully Qualified Domain Names (FQDNs, making them vulnerable to threats.

Innovation Solution

A hybrid WAF is introduced that runs inside the container-based architecture, acting as a proxy and providing direct access to web applications, enabling protection both within and outside the container environment by routing traffic through IP addresses or FQDNs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional WAF products are used to protect web applications, then web applications running on bare-metal servers or virtual machines can be protected, but web applications in container-based environments cannot be protected because they cannot be directly accessed through IP addresses or FQDNs

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidcompatibility with container-based architecture
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary component (service mesh/proxy) that sits between the traditional WAF and containerized web applications. This intermediary translates internal service references to external IP addresses and FQDNs, enabling traditional WAF products to protect container-based applications without direct access requirements. The intermediary handles the address translation and routing, making the WAF adaptable to container environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal protection mechanism that works across multiple deployment environments (bare-metal servers, virtual machines, and container-based architectures). By designing the WAF system to support multiple access methods and deployment scenarios, it achieves versatility while maintaining security protection capabilities across different infrastructure types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If web applications are deployed in container-based architecture for flexibility and scalability, then deployment agility is improved, but direct access through IP addresses or FQDNs is lost making applications vulnerable to threats

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidexposure to network threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The service mesh acts as a mediator between external network traffic and containerized applications. It maintains the isolation benefits of containerization while providing a controlled access point that enables security monitoring and protection. The intermediary preserves deployment flexibility by not requiring changes to container architecture while simultaneously protecting against network threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network architecture into distinct layers: the containerized application layer, the service mesh/proxy layer, and the traditional WAF layer. This segmentation allows each layer to maintain its advantages - containers provide deployment flexibility, while the intermediary and WAF layers provide security protection, resolving the contradiction between flexibility and vulnerability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a hybrid WAF is deployed to protect both container-based and external web applications, then comprehensive security coverage is achieved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hybrid WAF system is designed with universal components that can handle both container-based and external web applications through a unified architecture. The service mesh and proxy mechanisms provide a common interface for different deployment scenarios, reducing the need for separate specialized systems and managing complexity while achieving comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20230319012A1Hybrid web application firewall
Publication Date: 2023.10.05 SOPHOS LTD
  • US20230319012A1 patent drawing
  • US20230319012A1 patent drawing
  • US20230319012A1 patent drawing

AI summary

Threat management devices and methods for a containerized firewall. The methods may include receiving instructions to configure a web application firewall being executed within a first container-based architecture, wherein the received instructions include changes to a previous network traffic policy; storing the received instructions as a changelog that indicates an updated network traffic policy to be implemented by the web application firewall; and communicating the updated network traffic policy to a first object store associated with the first container-based architecture and to a proxy service associated with the web application firewall. The methods may further include configuring the web application firewall based on the updated network traffic policy communicated to the proxy service; monitoring, using the web application firewall, first network traffic originating within the first container-based architecture and second network traffic originating external to the first container-based architecture; and processing the first network traffic or the second network traffic in accord with the updated network traffic policy.