Network Traffic Processing Across Virtual Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall systems are inadequate in handling disjoint routing and configuration domains in a scalable and efficient manner, particularly in managing virtual networking domains.

Innovation Solution

A method and system that process network content associated with multiple virtual domains by defining interfaces for each domain, initiating service processes, and using communication channels to transfer and process content based on specific policies, including anti-malware scanning and content filtering, while allowing separate policies for each domain and utilizing physical or logical interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewall systems process network traffic for multiple virtual domains, then security coverage is improved, but system complexity and processing overhead increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the firewall system into multiple virtual domains, where each domain is an isolated processing context with its own configuration policies. This segmentation allows the system to handle multiple domains independently, reducing the complexity of managing security policies across diverse networks while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a domain identifier as an intermediary mechanism that links network traffic to the appropriate virtual domain and its corresponding configuration policies. This intermediary enables the system to automatically route traffic to the correct domain without manual intervention, reducing system complexity while improving security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Use of energy by moving object

If a single service process handles all virtual domains, then resource utilization is improved, but processing efficiency for individual domains deteriorates

Engineering Contradiction:
Improveresource utilizationVSAvoidprocessing efficiency
Core Design Contradiction:
Use of energy by moving objectVSProductivity

Solution Approach 1:

The patent implements a dynamic service process model where service processes can be dynamically created, assigned to specific virtual domains, and terminated based on traffic patterns. This dynamic approach allows the system to optimize resource utilization by activating only the necessary service processes for active domains while maintaining high processing efficiency through dedicated processes for each domain.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates copies of service processes for different virtual domains when needed. Each domain can have its own service process copy that handles traffic specific to that domain, improving processing efficiency while the shared nature of the service process template maintains reasonable resource utilization.

Inventive Principle:
Principle #26Copying

3Measurement precision

If separate configuration policies are applied to each virtual domain, then security precision is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity precisionVSAvoidconfiguration management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal configuration management system that handles multiple virtual domains through a common interface and standardized policy structure. Each domain has its own precise configuration policies, but they are all managed through a unified system that reduces the complexity of configuring and maintaining security policies across multiple domains.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the system automatically monitors traffic patterns and domain performance, then adjusts configuration policy application accordingly. This feedback loop reduces the manual complexity of managing separate configurations for each domain while maintaining high security precision through automated policy enforcement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8234361B2Computerized system and method for handling network traffic
Publication Date: 2012.07.31 FORTINET INC
  • US8234361B2 patent drawing
  • US8234361B2 patent drawing
  • US8234361B2 patent drawing

AI summary

A computerized system and method for processing network content associated with multiple virtual domains. The processing may include anti-malware scanning and/or content filtering. The content associated with multiple domains may be processed in the same daemon process. In response to connection requests from virtual domains, the service process creates separate sockets to communicate with each virtual domain. A global configuration management module is used to provide configuration parameters for each session to the service process. A logging manager processes both the global logs and the logs from each virtual domain. Alternatively, the service process may initiate other service processes to handle incoming connections from one or more virtual domains, in order to better utilize resources in a multiple-CPU environment. Different service processes may be used to handle various aspects of content processes, for example one process may handle anti-malware scanning, while another process may handle content filtering.