Security Platform External Inline Traffic Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current firewall architectures face limitations in performing advanced security scanning and inline file blocking due to limited context and per-session state storage, which restricts the types of protocols and file types they can support, and lack inline file blocking capabilities.
Innovation Solution
Implementing a security platform with external inline processing of assembled selected traffic, where a subset of monitored network traffic is forwarded to a cloud-based security service for analysis, allowing for advanced payload inspection using machine learning models and enabling inline file blocking by assembling and processing whole payloads, reducing performance impact on the data plane.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If firewall performs basic packet filtering and routing functions, then network security protection is provided, but advanced security scanning and inline file blocking capabilities are limited due to per-session state storage constraints
Solution Approach 1:
The patent extracts the advanced security scanning and file assembly functions from the firewall device and relocates them to external cloud-based security services. The firewall focuses on packet filtering and routing, while external services handle complex file reconstruction and malware analysis, resolving the contradiction between security capability and device complexity.
Solution Approach 2:
The patent introduces an intermediary external processing unit that acts as a bridge between the firewall and cloud-based security services. This intermediary receives selected traffic subsets, assembles files, and forwards them for analysis, enabling advanced security scanning without increasing firewall complexity.
2Productivity
If firewall inspects traffic in real-time with limited state storage, then network performance is maintained, but ability to perform advanced payload inspection and machine learning analysis is restricted
Solution Approach 1:
The patent segments traffic inspection into two parts: real-time packet filtering at the firewall maintaining network throughput, and deferred deep payload inspection at external services. By dividing the inspection process, the system maintains productivity while enabling comprehensive payload analysis through file assembly and machine learning.
Solution Approach 2:
The patent performs preliminary packet filtering and selection at the firewall before forwarding selected traffic to external services for deep inspection. This preliminary action maintains network performance by processing only necessary traffic externally, while enabling thorough payload inspection through subsequent file assembly and analysis.
3Reliability
If firewall processes complete files for security analysis, then detection accuracy improves, but per-session resource limitations are exceeded and network performance degrades
Solution Approach 1:
The patent extracts complete file assembly and analysis from the firewall's per-session processing and relocates it to external cloud-based services. This extraction enables reliable threat detection through complete file inspection while maintaining session processing speed at the firewall by handling only packet-level operations locally.
Solution Approach 2:
The patent creates a copy of selected traffic subsets and forwards them to external processing units for complete file assembly and analysis. The original traffic flow continues through the firewall without waiting for external analysis, maintaining session processing speed while enabling accurate threat detection through comprehensive external inspection.
Data Source
AI summary
Techniques for a security platform with external inline processing of assembled selected traffic are disclosed. In some embodiments, a system/method/computer program product for providing a security platform with external inline processing of assembled selected traffic includes monitoring network traffic of a session at a security platform; selecting a subset of the monitored network traffic associated with the session to send to a cloud-based security service for analysis based on a security policy, wherein the selected subset of the monitored network traffic is proxied to the cloud-based security service; and receiving, from the cloud-based security service, results of the analysis based on the security policy, and performing a responsive action based on the results of the analysis based on the security policy.


