Network Security Device Failover Flow Record Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security systems, such as firewalls and intrusion detection systems, face challenges in efficiently managing complex security policies and detecting network security intrusions due to slow speeds and complexity, especially in large networks, and proxy servers are limited in detecting intrusions at lower protocol layers.
Innovation Solution
A system and method for inspecting packets using a primary security apparatus that maintains flow information for a group of devices, with a secondary apparatus capable of processing packets during failover events and sharing flow records to ensure seamless operation and enhanced security monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packet filters are used to defend trusted networks from untrusted networks, then network security is improved, but processing speed decreases and management becomes difficult in large networks with complex security policies
Solution Approach 1:
The patent segments the network into trusted and untrusted zones using multiple packet filters arranged in series. Each filter handles specific security policies, dividing the complex security management task into manageable segments that can be processed independently, thus maintaining security while improving processing efficiency
Solution Approach 2:
The patent implements preliminary packet filtering at the network perimeter before packets enter the trusted network. By performing security checks and policy enforcement in advance, the system prevents malicious packets from consuming internal network resources, thereby improving overall processing speed while maintaining security
2Reliability
If proxy servers are used to insulate trusted networks from untrusted networks, then security is improved, but processing speed decreases due to additional protocol stack overhead
Solution Approach 1:
The patent uses packet filters as intermediary devices that operate at the network layer rather than requiring full protocol stack processing like traditional proxies. These intermediaries perform selective packet inspection and filtering without the overhead of maintaining complete protocol state machines, thus providing security isolation while maintaining processing speed
Solution Approach 2:
The patent replaces the mechanical protocol stack processing of traditional proxies with a more efficient packet filtering mechanism that operates directly on network layer packets. This substitution eliminates the need for application-layer protocol interpretation while maintaining security functionality, thereby improving processing speed
3Ease of operation
If conventional routers are used to forward packets based on destination address, then routing simplicity is maintained, but network policy enforcement capability is limited
Solution Approach 1:
The patent enhances conventional routers with multi-functionality by integrating packet filtering and security policy enforcement capabilities into the routing infrastructure. The router performs both traditional destination-based forwarding and security policy evaluation, allowing a single device to handle multiple networking functions without sacrificing routing simplicity
Data Source
AI summary
Methods and apparatuses for inspecting packets are provided. A primary security system may be configured for processing packets. The primary security system may be operable to maintain flow information for a group of devices to facilitate processing of the packets. A secondary security system may be designated for processing packets upon a failover event. Flow records may be shared from the primary security system with the secondary security system.


