Real-time Reconfigurable Web Application Firewall for Distributed Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed platforms, such as content delivery networks (CDNs), face challenges in protecting customer content and services from malicious attacks as existing firewall solutions are not customizable and cannot simultaneously support multiple customers with different security requirements, and there is a need for real-time reconfiguration to address security shortfalls.
Innovation Solution
A real-time reconfigurable web application firewall (WAF) for distributed platforms that allows each customer to define and enforce customized firewall rules and policies on a per-customer basis, enabling simultaneous production and audit profiles to secure assets while testing new protections without compromising existing configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a one-size-fits-all firewall solution is applied to all customers at a PoP, then device complexity is reduced and ease of operation is improved, but security effectiveness deteriorates because different customers have different security requirements
Solution Approach 1:
The patent segments the firewall system into multiple independent virtual firewall instances, where each instance is dedicated to a specific customer. This segmentation allows each customer to have customized security rules and policies while the overall system remains manageable through centralized configuration. The virtual firewall instance acts as an isolated environment that enforces customer-specific security requirements without interfering with other customers.
Solution Approach 2:
The patent implements a universal firewall platform that can serve multiple customers simultaneously through virtualization. The underlying firewall infrastructure provides multi-functionality by supporting different customer configurations, rule sets, and security policies within the same physical or logical system. This allows the firewall to be universally applicable across multiple customers while maintaining individual customization.
2Reliability
If customized firewall rules are implemented for each customer, then security effectiveness is improved, but device complexity and ease of operation worsen due to multiple configurations
Solution Approach 1:
The patent segments the firewall system into multiple independent virtual firewall instances, where each instance is dedicated to a specific customer. This segmentation allows each customer to have customized security rules and policies while the overall system remains manageable through centralized configuration. The virtual firewall instance acts as an isolated environment that enforces customer-specific security requirements without interfering with other customers.
Solution Approach 2:
The patent introduces a configuration management system that acts as an intermediary between administrators and the multiple virtual firewall instances. This intermediary automates the deployment, management, and coordination of customized firewall rules across different customer instances, reducing the operational complexity that would otherwise result from managing multiple custom configurations manually.
3Speed
If new firewall protections are deployed immediately, then response to security threats is improved, but reliability worsens due to potential errors in new configurations
Solution Approach 1:
The patent implements a staging environment that allows new firewall rules and configurations to be tested and validated before being deployed to production. This preliminary action enables security teams to verify the correctness and safety of new protections in a controlled environment that mirrors the production system, thereby preventing potentially erroneous configurations from compromising system reliability while still enabling rapid response to security threats through efficient promotion processes.
Data Source
AI summary
Some embodiments provide reconfigurable web application firewall (WAF) functionality across a distributed platform. Specifically, the WAF function at each distributed platform server is customizable on a per customer and per inbound message basis. When a server receives an inbound message, the server identities the content or services of which specific customer are implicated by the inbound message. The server screens the inbound message for attacks using a first set of rules and policies defined as part of a production profile from a WAF instance defined by the specific customer while contemporaneously testing the inbound message against a second set of rules and polices defined as part of an audit profile from the same WAF instance. In this manner, the specific customer tests the audit profile rules and policies while still receiving the protections of the production profile rules and policies.


