Network Security Device Selective Feature Application

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems consume significant system resources by deploying all security features for every URL accessed, regardless of whether the destination is trusted or malicious, leading to performance issues.

Innovation Solution

A network security device selectively enables or disables security features based on the trust level of the destination URL, intercepting network traffic and using a trusted network parameters database to determine whether to apply security features, thereby optimizing resource utilization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all security features are deployed for every URL accessed, then security protection is improved, but system resource consumption increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies different security feature sets to different URL categories. Trusted URLs receive minimal or no security features, while untrusted URLs receive full security inspection. This local differentiation resolves the contradiction by optimizing resource usage for trusted sites while maintaining security for untrusted sites.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts the application of security features based on real-time URL trust assessment. The network security device evaluates each URL and adaptively enables or disables security features accordingly, rather than using a static all-or-nothing approach. This dynamic adjustment resolves the contradiction between security and resource consumption.

Inventive Principle:
Principle #15Dynamics

2Reliability

If all security features are deployed for every URL accessed, then security protection is improved, but system performance deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By applying security features locally based on URL trust status, the system avoids unnecessary processing for trusted URLs, thereby improving overall system performance while maintaining security where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial security action (reduced or no security features) for trusted URLs and full security action for untrusted URLs. This partial application resolves the contradiction by eliminating excessive security processing for trusted sites while maintaining adequate protection for untrusted sites.

Inventive Principle:
Principle #16Partial or excessive action

3Use of energy by moving object

If security features are selectively disabled for trusted websites, then system resource consumption is reduced, but security coverage is compromised

Engineering Contradiction:
Improvesystem resource consumptionVSAvoidsecurity coverage
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The system performs preliminary trust assessment of URLs before determining security feature application. By pre-evaluating URL trust status using reputation databases and historical data, the system can confidently disable security features for trusted URLs without compromising security coverage, as the trust assessment is performed in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback from URL reputation databases, threat intelligence feeds, and historical security data to dynamically determine security feature application. This feedback mechanism ensures that security coverage is maintained for untrusted URLs while allowing resource optimization for trusted URLs.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10594708B2Providing security in a communication network
Publication Date: 2020.03.17 FORTINET INC
  • US10594708B2 patent drawing
  • US10594708B2 patent drawing
  • US10594708B2 patent drawing

AI summary

Systems and methods for optimizing system resources by selectively enabling various scanning functions of a network security device are provided. According to one embodiment, information specifying a set of reputable websites deemed to be trustworthy by one or more web filtering services is received by a network security device protecting a private network. One or more directives are received by the network security device from a network administrator via a GUI of the network security device identifying one or more security features that are to be disabled for the set of reputable websites. Network traffic is intercepted by the network security device from an external network. When it is determined by the network security device that the external network is among the set of reputable websites, the network security device foregoes application of the one or more identified security features to the network traffic.