SDN Fast Path Bypassing Security Appliances

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face inefficiencies due to the need for centralized security appliances and chokepoints, which can lead to high latency and costs, especially when dealing with large amounts of data and complex network topologies.

Innovation Solution

The integration of Software Defined Networks (SDN) with security appliances allows for dynamic reconfiguration of network paths, enabling a 'fast path' that bypasses security appliances after initial scanning, using SDN controllers and switches to optimize traffic routing and reduce reliance on centralized devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized security appliances are used to inspect all network traffic, then network security is improved, but latency increases and network throughput decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments network traffic into two categories: new connections requiring security inspection and established connections that can bypass security appliances. This segmentation allows security checks only when necessary, reducing latency for bulk data transfer while maintaining security for new connections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security appliance performs preliminary inspection of new connections before they are established. Once the connection is verified as secure, subsequent data transfer can proceed without further security appliance processing, eliminating repeated latency penalties.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If centralized security appliances are used to inspect all network traffic, then network security is improved, but network throughput decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments network traffic into new connections requiring security inspection and established connections that can bypass security appliances. This segmentation allows security checks only when necessary, reducing latency for bulk data transfer while maintaining security for new connections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts established connections from the security appliance processing path and routes them through a fast path using SDN. This removes the bottleneck of centralized security inspection for bulk data transfer, significantly improving network throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If centralized security appliances are used, then security policy enforcement is improved, but device complexity and infrastructure costs increase

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an SDN controller as an intermediary that manages the fast path routing. The SDN controller receives notifications from the security appliance about established connections and dynamically configures switches to create bypass paths, centralizing control without requiring complex configuration at each network device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The SDN controller provides universal control across the entire network infrastructure, managing fast path routing for multiple connections and security appliances through a single centralized system, reducing overall infrastructure complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11356413B2Providing a fast path between two entities
Publication Date: 2022.06.07 MCAFEE LLC
  • US11356413B2 patent drawing
  • US11356413B2 patent drawing
  • US11356413B2 patent drawing

AI summary

The present disclosure combines Software Defined Networks (SDN) concepts with Security concepts. The coordination between SDN and Security provides a myriad of advantageous use cases. One exemplary use case involves providing a fast path at network speeds using SDN by routing network traffic to bypass a security appliance once the security appliance determines that the security appliance no longer needs to inspect the network traffic. Another exemplary use case involves remote provisioning of security zones.