Packet Security Gateways for Scalable Network Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network protection solutions are largely reactive and unable to scale to larger networks due to the time required for high-resolution filtering of enormous traffic volumes, making proactive solutions infeasible, especially in large networks vulnerable to attacks like DDoS.

Innovation Solution

Implementing a system with packet security gateways associated with a security policy management server that receives dynamic security policies, allowing for packet transformation functions such as forwarding, dropping, or routing, and utilizing multiple gateways in series to reduce the number of rules applied to traffic, enabling efficient high-resolution filtering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If high-resolution filtering is applied to all network traffic in large networks, then network security protection capability is improved, but the time required for filtering increases making the solution infeasible

Engineering Contradiction:
Improvenetwork security protection capabilityVSAvoidfiltering time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the network into multiple zones with different security requirements and applies filtering at strategic boundary points rather than uniformly across all traffic. This allows high-resolution filtering to be applied selectively to critical traffic flows while using lower-resolution filtering for less sensitive traffic, thereby maintaining security capability while reducing overall filtering time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements differential filtering strategies where different filtering resolutions are applied to different network segments and traffic types based on their security sensitivity. Critical traffic receives high-resolution filtering while non-critical traffic receives lower-resolution filtering, optimizing the balance between security protection and processing speed.

Inventive Principle:
Principle #3Local quality

2Reliability

If proactive network protection is implemented, then attack prevention capability is improved, but the complexity and resource requirements increase making it untenable for large networks

Engineering Contradiction:
Improveattack prevention capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements proactive security measures by pre-configuring security policies, filtering rules, and response actions before attacks occur. Security policies are established in advance based on threat intelligence and historical data, enabling the system to automatically respond to known attack patterns without requiring complex real-time analysis, thereby reducing operational complexity while maintaining strong prevention capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables the network security system to automatically monitor, detect, and respond to threats without requiring constant human intervention. Automated policy enforcement, dynamic rule generation, and self-adjusting security parameters reduce the operational complexity and resource requirements while maintaining effective proactive protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12107893B2Methods and systems for protecting a secured network
Publication Date: 2024.10.01 CENTRIPETAL NETWORKS INC
  • US12107893B2 patent drawing
  • US12107893B2 patent drawing
  • US12107893B2 patent drawing

AI summary

Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets.