Network Security Device Zone Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security devices are limited in configuring multiple security profiles within a single device, failing to provide tailored security solutions for different sub-networks or zones within a network, especially in virtual environments where APIs for hypervisors are not scalable.
Innovation Solution
A network security device with independent threat management modules, including layer 2 and layer 3 modules, that allow for multiple security profiles to manage intra-zone and inter-zone traffic by performing specific security scans based on policies associated with each zone, enabling secure communication between computing devices within the same zone or across different zones without relying on scalable APIs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a network security device is configured with only one security profile, then the device complexity is reduced and ease of operation is improved, but the adaptability to different sub-networks and zones deteriorates
Solution Approach 1:
The patent divides the network into multiple zones (e.g., DMZ zone, internal zone, external zone) and configures different security profiles for each zone. Each zone has its own security policies, scanning rules, and threat management settings, allowing the security device to adapt to different security requirements without requiring a separate device for each zone.
Solution Approach 2:
The network security device is designed to provide multiple security profiles within a single device, enabling it to serve multiple zones and security requirements simultaneously. The device can apply different security policies, perform different types of security scanning, and enforce different access control rules for different zones, making it a universal security solution.
2Adaptability or versatility
If multiple security profiles are configured within a single network security device, then the adaptability to different zones is improved, but the device complexity increases
Solution Approach 1:
The patent implements segmentation by creating distinct security profiles for different zones, each with customized security parameters. The device maintains separate configuration sets for DMZ, internal, and external zones, allowing independent management of security policies without affecting other zones.
Solution Approach 2:
Each zone is assigned specific security characteristics and policies tailored to its requirements. For example, the DMZ zone may have more restrictive outbound traffic rules while the internal zone has different application scanning requirements. This local quality approach optimizes security for each zone without requiring uniform security settings across the entire network.
3Productivity
If hypervisor APIs are used to provide security in virtual environments, then ease of integration is improved, but scalability deteriorates due to limited API availability across different hypervisors
Solution Approach 1:
The patent creates a universal security device that operates independently of hypervisor-specific APIs. By implementing security functions at the network device level rather than relying on hypervisor integration, the solution achieves broad compatibility across different virtualization platforms including VMware, VirtualBox, and Hyper-V, significantly improving scalability.
Solution Approach 2:
The network security device acts as an intermediary between the virtualized environment and security policies. Instead of requiring direct integration with hypervisor APIs, the security device intercepts and inspects traffic at the network level, providing security without being constrained by hypervisor-specific interfaces.
Data Source
AI summary
Systems and methods for performing intra-zone and inter-zone security management in a network are provided. According to one embodiment, an association is formed by a network security device between a first zone including a first set of devices and a first set of security policies defining a first type of security scanning to be performed on packets originated within the first zone and between a second zone including a second set of devices and a second set of security policies defining a second type of security scanning to be performed on packets originated within the second zone. A first zone packet is received by the network security device. It is determined whether the destination is within the first zone. If so, then the first type of security scanning is performed. A second zone packet is received by the network security device. It is determined whether the destination is within the second zone. If so, then the second type of security scanning is performed.


