Process-Aware Identity Firewall for SDN Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing firewall systems in software-defined networking (SDN) environments lack the ability to effectively prevent malicious connections and fileless malware attacks by relying solely on identity-based filtering, which can be bypassed by attackers exploiting vulnerabilities in legitimate applications.
Innovation Solution
Implementing a process-aware identity firewall that correlates user, network, and process information to enforce granular access control by mapping identity information, network event information, and process information to specific firewall rules, thereby blocking unauthorized or potentially malicious processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If identity-based filtering is used in firewall systems, then ease of operation is improved, but security reliability deteriorates because attackers can bypass filtering by exploiting vulnerabilities in legitimate applications
Solution Approach 1:
The patent segments the firewall filtering mechanism from identity-based to process-aware identity-based filtering. By introducing process information as an additional segmentation dimension, the system can distinguish between legitimate and malicious processes even when they share the same identity, thereby maintaining ease of operation while improving security reliability through multi-dimensional rule matching
Solution Approach 2:
The patent adds a new dimension to the firewall rule matching by incorporating process information alongside identity information. This dimensional expansion transforms the filtering from two-dimensional (identity-based) to three-dimensional (identity + network + process), enabling the system to block malicious processes that exploit legitimate application vulnerabilities while maintaining user convenience
2Reliability
If process-aware identity firewall is implemented, then security reliability is improved, but device complexity increases due to correlation of multiple information types
Solution Approach 1:
The patent merges identity information, network information, and process information into a unified process-aware identity firewall rule matching mechanism. By combining these information types into a single correlated analysis framework, the system achieves improved security reliability without proportionally increasing device complexity, as the merging allows shared processing infrastructure across different information dimensions
Solution Approach 2:
The patent creates a universal firewall rule matching mechanism that handles multiple information types (identity, network, process) through a single correlated analysis framework. This multi-functional approach allows the same firewall engine to process diverse information dimensions, reducing overall system complexity compared to implementing separate filtering mechanisms for each information type
3Reliability
If granular access control is enforced through process-aware identity firewall, then security reliability is improved, but productivity decreases due to more precise filtering requirements
Solution Approach 1:
The patent implements preliminary action by pre-defining process-aware identity firewall rules that correlate identity, network, and process information before security events occur. This allows the system to automatically enforce granular access control decisions in real-time without requiring complex analysis during traffic processing, thereby maintaining high productivity while achieving improved security reliability through pre-established correlation frameworks
Data Source
AI summary
Example methods and systems for implementing an process-aware identity firewall are described. In one example, a computer system may detect a request for a virtualized computing instance to access a resource. The computer system may obtain (a) identity information identifying a user or a user device associated with the virtualized computing instance and (b) process information associated with a process that initiates the request to access the resource. The computer system may map the identity information, the network event information and the process information to an identity firewall rule that includes at least (a) a first parameter that is mappable to the identity information, (b) a second parameter that is mappable to the network event information and (c) a third parameter that is mappable to the process information. The identity firewall rule may be applied to allow or block the request to access the resource.


