Unified Security Gateway for IPv4 and IPv6 Traffic Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional firewalls and proxies operate independently and cannot effectively classify and manage network traffic across all OSI layers, especially for IPv4 and IPv6 environments, lacking the ability to associate specific applications with traffic flows and enforce comprehensive security policies.

Innovation Solution

A next-generation security gateway that integrates firewall and UTM infrastructures with application proxy technology, enabling classification of traffic flows by specific applications and enforcing policies across OSI layers L3-L7, with features like real-time rating, anti-virus scanning, and data loss prevention, and allowing dynamic updates based on observed traffic patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional firewalls operate at packet level (L2-L4), then packet filtering speed is maintained, but ability to classify traffic by application and enforce granular policies is lost

Engineering Contradiction:
Improvepacket filtering speedVSAvoidapplication classification capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system segments the firewall functionality into multiple independent components: a stateful packet filter for L2-L4 traffic handling, and separate application proxies for L7 application-level inspection. Each component operates independently at its optimal layer, with the packet filter handling high-speed packet routing and application proxies providing deep application classification and policy enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a new dimension to traditional firewall operation by introducing application-layer (L7) inspection capabilities alongside the existing network-layer (L3) and transport-layer (L4) filtering. This multi-dimensional approach allows simultaneous operation at multiple OSI layers, combining fast packet filtering with application-aware policy enforcement without sacrificing speed in either domain.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If stateful firewalls maintain connection state information, then packet processing efficiency is improved, but ability to associate specific users with applications is lost

Engineering Contradiction:
Improvepacket processing efficiencyVSAvoiduser-application association accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

Application proxies serve as intermediaries between users and the stateful firewall. The proxies terminate application-layer connections, perform user authentication and application identification, then generate simplified connection requests that the stateful firewall can process efficiently. This intermediary layer preserves user-application association information while enabling fast stateful packet processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple independent security devices are deployed, then specialized functions are maintained, but system complexity and coordination overhead increase

Engineering Contradiction:
Improvespecialized security functionsVSAvoidsystem coordination complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system merges the stateful firewall and application proxies into a single integrated security gateway appliance. This unified architecture eliminates the need for complex coordination between separate devices, as all security functions operate within one system with shared state information and centralized policy management, while still maintaining the specialized capabilities of both packet filtering and application-layer inspection.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9973540B2System and method for building intelligent and distributed L2-L7 unified threat management infrastructure for IPV4 and IPV6 environments
Publication Date: 2018.05.15 CA TECH INC
  • US9973540B2 patent drawing
  • US9973540B2 patent drawing
  • US9973540B2 patent drawing

AI summary

A security gateway appliance is configured to evaluate network traffic according to security rules that classify traffic flows according to specifically identified application programs responsible for producing and/or consuming the network traffic and to enforce policies in accordance with network traffic classifications. The appliance includes an on-box anti-virus/anti-malware engine, on-box data loss prevention engine and on-box authentication engine. One or more of these engines is informed by an on-box dynamic real tie rating system that allows for determined levels of scrutiny to be paid to the network traffic. Security gateways of this type can be clustered together to provide a set of resources for one or more networks, and in some instances as the backbone of a cloud-based service.