Multi-Perimeter Network Security Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies, such as firewalls and intrusion detection devices, are inadequate in preventing and mitigating advanced network attacks like denial of service attacks, which can overwhelm servers and disrupt network operations, and require frequent system patching and upgrading that can be disruptive.

Innovation Solution

A multi-layered security system comprising a CDN perimeter, a mitigation perimeter, and a hierarchy perimeter, where CDN devices provide initial protection, mitigation devices process and filter malicious traffic, and hierarchy devices act as reverse proxies to obscure the customer network's presence and ensure continuous operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current perimeter security technologies (firewalls, intrusion detection devices) are used, then basic network protection is provided, but they cannot effectively protect against advanced network attacks like denial of service attacks

Engineering Contradiction:
Improvenetwork protection effectivenessVSAvoidcapability against advanced attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security system into multiple specialized components: CDN devices for content delivery and initial filtering, mitigation devices for attack detection and traffic scrubbing, and hierarchy devices for routing and orchestration. This segmentation allows each component to be optimized for specific functions, enabling effective protection against advanced attacks while maintaining basic firewall capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces mitigation devices as intermediaries between the external network and the customer network. These mitigation devices act as mediators that receive, analyze, and filter malicious traffic before it reaches the customer network, while allowing legitimate traffic to pass through. This intermediary layer provides adaptability against advanced attacks without compromising the effectiveness of perimeter security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If system patching and upgrading are performed frequently to maintain security, then security system effectiveness is improved, but network service disruption occurs

Engineering Contradiction:
Improvesecurity system effectivenessVSAvoidnetwork service continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by maintaining multiple versions of security system components and pre-configuring backup devices. Before performing patching or upgrading operations, the system prepares replacement components and ensures backup devices are ready to take over immediately. This allows security updates to be applied without causing network service disruption, as the multi-layered architecture enables seamless failover between devices.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If overprovisioning is used to protect against large attacks, then adequate protection is provided, but network costs increase significantly

Engineering Contradiction:
Improveprotection adequacyVSAvoidnetwork infrastructure resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements dynamic resource allocation where the security system can adapt its capacity in real-time based on attack conditions. During normal operations, the system uses minimal resources efficiently. When attacks are detected, the system dynamically activates additional mitigation capacity and redirects traffic through mitigation devices. This dynamic approach provides adequate protection against large attacks without requiring permanent overprovisioning of infrastructure resources.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent makes network devices multi-functional to reduce overall infrastructure requirements. CDN devices not only deliver content but also perform initial attack filtering. Hierarchy devices handle both routing and coordination of security responses. Mitigation devices can process multiple types of attacks using the same scrubbing infrastructure. This universality allows the system to provide comprehensive protection without requiring separate dedicated resources for each function, reducing total infrastructure needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7730536B2Security perimeters
Publication Date: 2010.06.01 PALO ALTO NETWORKS INC
  • US7730536B2 patent drawing
  • US7730536B2 patent drawing
  • US7730536B2 patent drawing

AI summary

A security system that is associated with a customer network includes first, second, and third security perimeters. The first security perimeter includes a set of content delivery network (CDN) devices configured to provide first protection against a network attack associated with the customer network. The second security perimeter includes a set of mitigation devices configured to provide second protection in terms of mitigation services as a result of a network attack associated with the customer network. The third security perimeter includes a set of hierarchy devices configured to provide third protection against a network attack associated with the customer network.