Perimeter Security Appliance Internal Traffic Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Perimeter network security devices have limited visibility and effectiveness in managing internal network traffic within a private network, as they only inspect external traffic, leading to evasion of malicious activities by internal hosts.
Innovation Solution
A perimeter network security appliance receives internal network information from Layer 2/3 network devices, derives the network topology, and enforces traffic policies to control and block malicious internal traffic, enhancing visibility and security by interacting with these devices to manage both internal and external traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a perimeter network security device is deployed to inspect external traffic, then external network traffic security is improved, but visibility into internal network traffic remains limited
Solution Approach 1:
The patent introduces an intermediary mechanism where Layer 2/3 network devices forward internal network information to the perimeter security device. This allows the security device to gain visibility into internal traffic without directly intercepting or inspects every internal packet, resolving the contradiction between maintaining external security focus and gaining internal visibility.
Solution Approach 2:
The system implements feedback loops where the perimeter security device receives internal network information from network devices, analyzes it, and sends back control instructions. This feedback mechanism enables continuous improvement of security policies based on actual internal traffic patterns, addressing the visibility limitation.
2Productivity
If internal network traffic is switched by Layer 2/3 network devices without passing through the security device, then network performance is improved, but security inspection of internal traffic is lost
Solution Approach 1:
The patent extracts security inspection functionality from the traditional packet-path approach and implements it through information extraction. Layer 2/3 network devices extract and forward relevant internal network information (flow data, topology, configuration) to the perimeter security device for analysis, maintaining high throughput while enabling security inspection.
Solution Approach 2:
The system segments the security function into two parts: network devices handle traffic switching and collect information, while the perimeter security device handles security analysis. This segmentation allows traffic to flow efficiently through network devices while security inspection occurs at the perimeter through information analysis rather than packet interception.
3Device complexity
If the perimeter security device only inspects external traffic, then device complexity is reduced, but effectiveness in preventing internal malicious activity is worsened
Solution Approach 1:
The patent makes the perimeter security device universal by enabling it to perform multiple functions: inspecting external traffic as before, and now also analyzing internal network information received from network devices. This multi-functionality increases the device's effectiveness against internal threats without requiring complex distributed architecture throughout the network.
Data Source
AI summary
Systems and methods for managing network traffic by a perimeter network security device based on internal network traffic or configuration information are provided. According to one embodiment, a network security appliance of a private network receives internal network information collected by multiple Layer 2/3 network devices of the private network. The Layer 2/3 network devices switch/route internal network traffic among multiple internal host devices without the network traffic passing through the network security device and switch/route external network traffic between the network security appliance and the internal host devices. A topology of the private network is derived based on the internal network information. Existence of potential malicious activity involving an internal host device is identified by evaluating the internal network information. Responsive thereto (i) a traffic policy is created to control transmission of network traffic associated with the internal host device; and (ii) the traffic policy is enforced.


