Process-Aware Identity Firewall for SDN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall systems in software-defined networking (SDN) environments lack the ability to effectively prevent malicious connections and fileless malware attacks by relying solely on identity-based filtering, which can be bypassed by attackers exploiting vulnerabilities in legitimate applications.

Innovation Solution

Implementing a process-aware identity firewall that correlates user, network, and process information to enforce granular access control by mapping identity information, network event information, and process information to specific firewall rules, thereby blocking unauthorized or potentially malicious processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identity-based filtering is used in firewall systems, then ease of operation is improved, but security reliability deteriorates because attackers can bypass filtering by exploiting vulnerabilities in legitimate applications

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the firewall filtering mechanism from identity-based to process-aware identity-based filtering. By introducing process information as an additional segmentation dimension, the system can distinguish between legitimate and malicious processes even when they share the same identity, thereby maintaining ease of operation while improving security reliability through multi-dimensional rule matching

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to the firewall rule matching by incorporating process information alongside identity information. This dimensional expansion transforms the filtering from two-dimensional (identity-based) to three-dimensional (identity + network + process), enabling the system to block malicious processes that exploit legitimate application vulnerabilities while maintaining user convenience

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If process-aware identity firewall is implemented, then security reliability is improved, but device complexity increases due to correlation of multiple information types

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges identity information, network information, and process information into a unified process-aware identity firewall rule matching mechanism. By combining these information types into a single correlated analysis framework, the system achieves improved security reliability without proportionally increasing device complexity, as the merging allows shared processing infrastructure across different information dimensions

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal firewall rule matching mechanism that handles multiple information types (identity, network, process) through a single correlated analysis framework. This multi-functional approach allows the same firewall engine to process diverse information dimensions, reducing overall system complexity compared to implementing separate filtering mechanisms for each information type

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If granular access control is enforced through process-aware identity firewall, then security reliability is improved, but productivity decreases due to more precise filtering requirements

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-defining process-aware identity firewall rules that correlate identity, network, and process information before security events occur. This allows the system to automatically enforce granular access control decisions in real-time without requiring complex analysis during traffic processing, thereby maintaining high productivity while achieving improved security reliability through pre-established correlation frameworks

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250112892A1Process-Aware Identity Firewall
Publication Date: 2025.04.03 VMWARE INC
  • US20250112892A1 patent drawing
  • US20250112892A1 patent drawing
  • US20250112892A1 patent drawing

AI summary

Example methods and systems for implementing an process-aware identity firewall are described. In one example, a computer system may detect a request for a virtualized computing instance to access a resource. The computer system may obtain (a) identity information identifying a user or a user device associated with the virtualized computing instance and (b) process information associated with a process that initiates the request to access the resource. The computer system may map the identity information, the network event information and the process information to an identity firewall rule that includes at least (a) a first parameter that is mappable to the identity information, (b) a second parameter that is mappable to the network event information and (c) a third parameter that is mappable to the process information. The identity firewall rule may be applied to allow or block the request to access the resource.