Identity Centric Firewall Segmentation for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures, including the Kerberos protocol and traditional firewalls, are insufficient in detecting and preventing malicious or unwanted access to network resources, as they lack the necessary logic to identify and respond to malicious traffic effectively.

Innovation Solution

An Identity Centric Firewall (ICF) system that operates inline or in sniffer mode, utilizing four modules: the Traffic Extractor, Detection Engine, Enforcement/Prevention, and Management Module, to analyze network traffic, enforce policies, and adapt to changing behavior by learning normal patterns and updating rules dynamically, leveraging Active Directory information and polymorphism to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls operate in-line to block malicious traffic, then security protection is improved, but network performance and usability deteriorate due to all traffic requiring inspection

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments network traffic into different categories (e.g., authentication traffic versus general data traffic) and applies different security inspection levels to each segment. Critical authentication traffic receives full inspection while less critical traffic receives reduced inspection, resolving the contradiction between comprehensive security and network performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The firewall applies differentiated security policies to different local traffic characteristics rather than uniform inspection. The system analyzes traffic patterns, source/destination addresses, and protocol types to apply appropriate inspection depth locally, improving performance for trusted traffic while maintaining security for suspicious traffic.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If firewalls inspect all network traffic to detect malicious behavior, then detection capability is improved, but processing time and system resources increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary classification of network traffic into trust categories before full inspection. By pre-sorting traffic based on source/destination relationships and established patterns, the system can quickly identify benign traffic that doesn't require deep inspection, reducing processing time while maintaining detection capability for malicious traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The inspection depth and processing intensity are dynamically adjusted based on real-time traffic characteristics and risk assessment. The system continuously learns from network patterns and adapts its inspection strategy, applying more resources to high-risk traffic while reducing resources for low-risk traffic, thus optimizing detection capability versus processing time.

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If static firewall rules are used to maintain security policies, then implementation simplicity is improved, but adaptability to changing threats deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidadaptability to changing threats
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system incorporates feedback mechanisms that continuously monitor network traffic patterns, threat detections, and security events. This feedback loops back into the rule generation process, enabling automatic updates of firewall rules based on observed behavior and emerging threats, thus maintaining adaptability while keeping the system relatively simple to operate.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The firewall system performs self-learning and self-adjustment by automatically analyzing traffic patterns and generating updated security rules without requiring constant manual reconfiguration. The system serves itself by maintaining its own knowledge base of network behavior and threat patterns, providing adaptability while simplifying user interaction.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11503043B2System and method for providing an in-line and sniffer mode network based identity centric firewall
Publication Date: 2022.11.15 CROWDSTRIKE
  • US11503043B2 patent drawing
  • US11503043B2 patent drawing
  • US11503043B2 patent drawing

AI summary

The instant disclosure is directed to an attack/unwanted activity detecting firewall for use in protecting authentication-based network resources. The instant system is adapted for installation inline or in sniffer mode. In various embodiments, defined rules are applied to network traffic to determine whether certain types of attacks are occurring on the network resources. If one such attack is detected, the system provides for several potential responses, including for example disconnecting the attacking remote machine, requiring the user at that machine to re-authenticate, and/or requiring a second factor of authentication from the user at that machine. In some example embodiments, regardless of any activity required of a user at the remote machine suspected of malicious behavior, the disclosed system generates an alarm or other alert for presentation as appropriate, such as via a graphical user interface or a third-party system using an API.