Network Session Data Sharing for Next-Generation Firewalls

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Next-generation firewall (NGFW) devices face significant computing resource and network bandwidth consumption due to CPU-intensive application classification processes, particularly for peer-to-peer (P2P) applications, which can lead to performance degradation and increased resource utilization.

Innovation Solution

NGFWs are configured to export and share application classification results with other devices in the network, allowing them to reuse this information for related traffic flows without performing redundant classification operations, thereby reducing the computational load and conserving bandwidth.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If NGFW devices individually process and classify all network traffic using dynamic application classification algorithms, then application identification accuracy is improved, but computing resource consumption and network bandwidth consumption increase significantly

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidcomputing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

Multiple NGFW devices are merged into a collaborative classification system where they share application classification results through inter-device communication. When one NGFW device classifies an application, the classification result is propagated to other NGFW devices, allowing them to reuse the classification without performing independent CPU-intensive analysis, thus reducing overall computing resource consumption while maintaining identification accuracy

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The first NGFW device performs application classification in advance and exports the classification result to subsequent NGFW devices in the traffic path. This preliminary action eliminates the need for redundant classification operations downstream, reducing computing resource consumption while ensuring accurate application identification at each device

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple NGFW devices independently perform application classification for the same traffic flows, then application classification reliability is improved, but network bandwidth consumption increases due to redundant processing

Engineering Contradiction:
Improveapplication classification reliabilityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

NGFW devices are combined into a coordinated system where classification responsibilities are shared. Instead of each device independently processing the same traffic flows, they collaborate by exporting and importing classification results, reducing redundant network processing while maintaining reliable application identification through multiple devices working together

Inventive Principle:
Principle #5Merging (Combining)

3Use of energy by moving object

If NGFW devices export and share application classification results through inter-device communication, then computing resource consumption is reduced, but device complexity increases

Engineering Contradiction:
Improvecomputing resource consumptionVSAvoidsystem coordination complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The NGFW devices implement universal classification result sharing capabilities that work across different device instances. By establishing a standardized mechanism for exporting and importing application classification results, the system achieves multi-functionality where each device can both generate and consume classification data, reducing computing overhead without requiring complex custom integration between devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3188440B1Network session data sharing
Publication Date: 2021.03.10 JUNIPER NETWORKS INC
  • EP3188440B1 patent drawingFigure 1A
  • EP3188440B1 patent drawingFigure 1B
  • EP3188440B1 patent drawingFigure 1C

AI summary

In general, techniques for sharing of network session data are described. The techniques enable security devices (12B) to leverage application classification information in a federated manner. An example security device includes a memory and one or more processors. The processor(s) are configured to receive data representative of an application classification for a first packet flow (2) from a second security device (12A), to receive data of a second packet flow (4), and, when the second packet flow corresponds to the first packet flow, to monitor the data of the second packet flow based on the application classification for the first packet flow without determining an application classification for the second packet flow.