Network Session Data Sharing for Next-Generation Firewalls
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Next-generation firewall (NGFW) devices face significant computing resource and network bandwidth consumption due to CPU-intensive application classification processes, particularly for peer-to-peer (P2P) applications, which can lead to performance degradation and increased resource utilization.
Innovation Solution
NGFWs are configured to export and share application classification results with other devices in the network, allowing them to reuse this information for related traffic flows without performing redundant classification operations, thereby reducing the computational load and conserving bandwidth.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If NGFW devices individually process and classify all network traffic using dynamic application classification algorithms, then application identification accuracy is improved, but computing resource consumption and network bandwidth consumption increase significantly
Solution Approach 1:
Multiple NGFW devices are merged into a collaborative classification system where they share application classification results through inter-device communication. When one NGFW device classifies an application, the classification result is propagated to other NGFW devices, allowing them to reuse the classification without performing independent CPU-intensive analysis, thus reducing overall computing resource consumption while maintaining identification accuracy
Solution Approach 2:
The first NGFW device performs application classification in advance and exports the classification result to subsequent NGFW devices in the traffic path. This preliminary action eliminates the need for redundant classification operations downstream, reducing computing resource consumption while ensuring accurate application identification at each device
2Reliability
If multiple NGFW devices independently perform application classification for the same traffic flows, then application classification reliability is improved, but network bandwidth consumption increases due to redundant processing
Solution Approach 1:
NGFW devices are combined into a coordinated system where classification responsibilities are shared. Instead of each device independently processing the same traffic flows, they collaborate by exporting and importing classification results, reducing redundant network processing while maintaining reliable application identification through multiple devices working together
3Use of energy by moving object
If NGFW devices export and share application classification results through inter-device communication, then computing resource consumption is reduced, but device complexity increases
Solution Approach 1:
The NGFW devices implement universal classification result sharing capabilities that work across different device instances. By establishing a standardized mechanism for exporting and importing application classification results, the system achieves multi-functionality where each device can both generate and consume classification data, reducing computing overhead without requiring complex custom integration between devices
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
In general, techniques for sharing of network session data are described. The techniques enable security devices (12B) to leverage application classification information in a federated manner. An example security device includes a memory and one or more processors. The processor(s) are configured to receive data representative of an application classification for a first packet flow (2) from a second security device (12A), to receive data of a second packet flow (4), and, when the second packet flow corresponds to the first packet flow, to monitor the data of the second packet flow based on the application classification for the first packet flow without determining an application classification for the second packet flow.