Predictive Security Policy Selection for Firewall Performance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls face performance impairments due to the time-consuming and resource-intensive security inspections when comparing traffic against large sets of Intrusion Prevention System (IPS) signatures, especially when dealing with unsuspicious traffic.

Innovation Solution

Implementing an apparatus with a storage device and physical processor that analyzes unknown packet flows, identifies characteristics, predictsively selects a security policy from a set of stored policies, and applies relevant security actions, thereby reducing the number of IPS signatures used in inspections to a subset most relevant to the flow, improving firewall performance and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security inspection against large sets of IPS signatures is performed on all traffic, then security detection accuracy is improved, but firewall performance and processing speed deteriorate

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidfirewall performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the large set of IPS signatures into multiple subsets based on traffic characteristics. Different signature subsets are applied to different types of traffic flows, allowing comprehensive security inspection to be divided into manageable portions that can be processed efficiently without sacrificing detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by performing security inspection only on the portion of traffic that requires it, rather than inspecting all traffic with the full signature set. Traffic is analyzed to determine which subsets require inspection, and only those specific subsets are inspected using relevant signature subsets, reducing overall processing load while maintaining security effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If comprehensive security inspection against large sets of IPS signatures is performed on all traffic, then security coverage is improved, but computing resource consumption increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by tailoring the security inspection intensity to the specific characteristics of each traffic flow. Different traffic types receive different levels of inspection with appropriately selected signature subsets, ensuring that computing resources are concentrated on traffic that requires thorough analysis while using minimal resources for traffic that requires less scrutiny.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs partial security inspection by applying only the necessary subset of signatures to each traffic flow rather than the complete signature set. This selective approach ensures comprehensive security coverage for all traffic while significantly reducing overall computing resource consumption by avoiding redundant inspections.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security inspection is performed on unsuspicious traffic, then security thoroughness is improved, but processing efficiency deteriorates

Engineering Contradiction:
Improvesecurity thoroughnessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic security inspection by adjusting the inspection depth and signature subset based on real-time traffic analysis. Traffic is dynamically classified into different categories, and the inspection process is adapted accordingly - suspicious traffic receives thorough inspection while unsuspicious traffic receives streamlined inspection, optimizing the balance between security thoroughness and processing time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies partial inspection action by performing security checks only to the extent necessary for each traffic flow. Unsuspicious traffic undergoes minimal inspection with reduced signature subsets, while suspicious traffic receives comprehensive inspection. This approach maintains security thoroughness where needed while minimizing processing time for benign traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10735469B1Apparatus, system, and method for predictively enforcing security policies on unknown flows
Publication Date: 2020.08.04 JUNIPER NETWORKS INC
  • US10735469B1 patent drawing
  • US10735469B1 patent drawing
  • US10735469B1 patent drawing

AI summary

The disclosed apparatus may include a storage device that stores a set of security policies. In this example, the apparatus may also include a physical processor that is communicatively coupled to the storage device. This physical processor may (1) analyze an unknown flow of packets that are destined for a target node within the network, (2) identify at least one characteristic of the unknown flow of packets based at least in part on the analysis, (3) predictively select, from the set of security policies stored in the storage device, a security policy to apply to the unknown flow of packets based at least in part on the characteristic of the unknown flow of packets, and then (4) perform at least one security action defined by the predictively selected security policy on the unknown flow of packets. Various other apparatuses, systems, and methods are also disclosed.