Real-time Reconfigurable Web Application Firewall for Distributed Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed platforms, such as content delivery networks (CDNs), face challenges in protecting customer content and services from malicious attacks as existing firewall solutions are not customizable and cannot simultaneously support multiple customers with different security requirements, and there is a need for real-time reconfiguration to address security shortfalls.

Innovation Solution

A real-time reconfigurable web application firewall (WAF) for distributed platforms that allows each customer to define and enforce customized firewall rules and policies on a per-customer basis, enabling simultaneous production and audit profiles to secure assets while testing new protections without compromising existing configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a one-size-fits-all firewall solution is applied to all customers at a PoP, then device complexity is reduced and ease of operation is improved, but security effectiveness deteriorates because different customers have different security requirements

Engineering Contradiction:
Improvefirewall configuration simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the firewall system into multiple independent virtual firewall instances, where each instance is dedicated to a specific customer. This segmentation allows each customer to have customized security rules and policies while the overall system remains manageable through centralized configuration. The virtual firewall instance acts as an isolated environment that enforces customer-specific security requirements without interfering with other customers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal firewall platform that can serve multiple customers simultaneously through virtualization. The underlying firewall infrastructure provides multi-functionality by supporting different customer configurations, rule sets, and security policies within the same physical or logical system. This allows the firewall to be universally applicable across multiple customers while maintaining individual customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If customized firewall rules are implemented for each customer, then security effectiveness is improved, but device complexity and ease of operation worsen due to multiple configurations

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the firewall system into multiple independent virtual firewall instances, where each instance is dedicated to a specific customer. This segmentation allows each customer to have customized security rules and policies while the overall system remains manageable through centralized configuration. The virtual firewall instance acts as an isolated environment that enforces customer-specific security requirements without interfering with other customers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a configuration management system that acts as an intermediary between administrators and the multiple virtual firewall instances. This intermediary automates the deployment, management, and coordination of customized firewall rules across different customer instances, reducing the operational complexity that would otherwise result from managing multiple custom configurations manually.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If new firewall protections are deployed immediately, then response to security threats is improved, but reliability worsens due to potential errors in new configurations

Engineering Contradiction:
Improvesecurity response timeVSAvoidconfiguration stability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements a staging environment that allows new firewall rules and configurations to be tested and validated before being deployed to production. This preliminary action enables security teams to verify the correctness and safety of new protections in a controlled environment that mirrors the production system, thereby preventing potentially erroneous configurations from compromising system reliability while still enabling rapid response to security threats through efficient promotion processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9660960B2Real-time reconfigurable web application firewall for a distributed platform
Publication Date: 2017.05.23 DRNC HOLDINGS INC
  • US9660960B2 patent drawing
  • US9660960B2 patent drawing
  • US9660960B2 patent drawing

AI summary

Some embodiments provide reconfigurable web application firewall (WAF) functionality across a distributed platform. Specifically, the WAF function at each distributed platform server is customizable on a per customer and per inbound message basis. When a server receives an inbound message, the server identities the content or services of which specific customer are implicated by the inbound message. The server screens the inbound message for attacks using a first set of rules and policies defined as part of a production profile from a WAF instance defined by the specific customer while contemporaneously testing the inbound message against a second set of rules and polices defined as part of an audit profile from the same WAF instance. In this manner, the specific customer tests the audit profile rules and policies while still receiving the protections of the production profile rules and policies.