Predictive Security Policy Selection for Firewall Performance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewalls face performance impairments due to the time-consuming and resource-intensive security inspections when comparing traffic against large sets of Intrusion Prevention System (IPS) signatures, especially when dealing with unsuspicious traffic.
Innovation Solution
Implementing an apparatus with a storage device and physical processor that analyzes unknown packet flows, identifies characteristics, predictsively selects a security policy from a set of stored policies, and applies relevant security actions, thereby reducing the number of IPS signatures used in inspections to a subset most relevant to the flow, improving firewall performance and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive security inspection against large sets of IPS signatures is performed on all traffic, then security detection accuracy is improved, but firewall performance and processing speed deteriorate
Solution Approach 1:
The patent segments the large set of IPS signatures into multiple subsets based on traffic characteristics. Different signature subsets are applied to different types of traffic flows, allowing comprehensive security inspection to be divided into manageable portions that can be processed efficiently without sacrificing detection accuracy.
Solution Approach 2:
The patent applies partial action by performing security inspection only on the portion of traffic that requires it, rather than inspecting all traffic with the full signature set. Traffic is analyzed to determine which subsets require inspection, and only those specific subsets are inspected using relevant signature subsets, reducing overall processing load while maintaining security effectiveness.
2Reliability
If comprehensive security inspection against large sets of IPS signatures is performed on all traffic, then security coverage is improved, but computing resource consumption increases
Solution Approach 1:
The patent applies local quality by tailoring the security inspection intensity to the specific characteristics of each traffic flow. Different traffic types receive different levels of inspection with appropriately selected signature subsets, ensuring that computing resources are concentrated on traffic that requires thorough analysis while using minimal resources for traffic that requires less scrutiny.
Solution Approach 2:
The patent performs partial security inspection by applying only the necessary subset of signatures to each traffic flow rather than the complete signature set. This selective approach ensures comprehensive security coverage for all traffic while significantly reducing overall computing resource consumption by avoiding redundant inspections.
3Reliability
If security inspection is performed on unsuspicious traffic, then security thoroughness is improved, but processing efficiency deteriorates
Solution Approach 1:
The patent implements dynamic security inspection by adjusting the inspection depth and signature subset based on real-time traffic analysis. Traffic is dynamically classified into different categories, and the inspection process is adapted accordingly - suspicious traffic receives thorough inspection while unsuspicious traffic receives streamlined inspection, optimizing the balance between security thoroughness and processing time.
Solution Approach 2:
The patent applies partial inspection action by performing security checks only to the extent necessary for each traffic flow. Unsuspicious traffic undergoes minimal inspection with reduced signature subsets, while suspicious traffic receives comprehensive inspection. This approach maintains security thoroughness where needed while minimizing processing time for benign traffic.
Data Source
AI summary
The disclosed apparatus may include a storage device that stores a set of security policies. In this example, the apparatus may also include a physical processor that is communicatively coupled to the storage device. This physical processor may (1) analyze an unknown flow of packets that are destined for a target node within the network, (2) identify at least one characteristic of the unknown flow of packets based at least in part on the analysis, (3) predictively select, from the set of security policies stored in the storage device, a security policy to apply to the unknown flow of packets based at least in part on the characteristic of the unknown flow of packets, and then (4) perform at least one security action defined by the predictively selected security policy on the unknown flow of packets. Various other apparatuses, systems, and methods are also disclosed.


