Web Firewall Daemon for Intelligent Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods fail to effectively detect and block intelligent web attacks without affecting web application stability or availability, and they require changes in IP and DNS information, which can lead to communication delays and increased costs, especially in cloud environments.

Innovation Solution

A system comprising a filter unit and a web firewall daemon that analyzes web request data to determine risks, modifies data as necessary, and transmits modified data, while maintaining existing network configurations and preventing SSL authentication exposure, all while being cost-effective and adaptable to cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewalls and intrusion detection systems are used to detect web attacks, then basic security is provided, but they cannot effectively handle intelligent attack methods that continuously discover and attack function-specific vulnerabilities

Engineering Contradiction:
Improveattack detection effectivenessVSAvoidcapability to handle intelligent attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the detection parameters from general network traffic analysis to specific web application behavior analysis. The web firewall daemon analyzes HTTP request parameters, URL patterns, and application-level protocols to detect intelligent attacks that evade conventional firewalls focused on lower-level network parameters.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces a web firewall daemon as an intermediary component between the web server and external requests. This daemon specifically handles web application protocol analysis and attack detection, bridging the gap between conventional firewalls and application-specific security needs without affecting overall system stability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If web security services are implemented using conventional methods, then attack protection is provided, but web application stability and availability are affected

Engineering Contradiction:
Improvesecurity protectionVSAvoidweb application stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent segments the security function into a separate web firewall daemon process that operates independently from the web application server. This segmentation allows security scanning and attack detection to occur in parallel without blocking or destabilizing the main application, maintaining both security and stability simultaneously.

Inventive Principle:
Principle #1Segmentation

3Reliability

If IP and DNS information are changed to provide web firewall services, then security service is provided, but communication delays occur and initial costs increase

Engineering Contradiction:
Improvesecurity service provisionVSAvoidcommunication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a self-service web firewall daemon that runs locally on the web server system rather than requiring external firewall services. This eliminates the need to change IP and DNS information, avoiding communication delays with external services while providing comprehensive security protection.

Inventive Principle:
Principle #25Self-service

4Reliability

If SSL authentication and personal keys are uploaded to web firewall service providers, then HTTPS security is provided, but SSL authentication and personal keys are exposed and initial cost increases

Engineering Contradiction:
ImproveHTTPS securityVSAvoidSSL key exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the SSL/TLS decryption and analysis capability into the local web firewall daemon, allowing inspection of encrypted traffic without exposing private keys to external service providers. The daemon can analyze HTTPS requests locally, eliminating the security risk of key exposure while maintaining encryption security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11171919B1Web attack detecting and blocking system and method thereof
Publication Date: 2021.11.09 F1 SECURITY INC
  • US11171919B1 patent drawing
  • US11171919B1 patent drawing

AI summary

A system for detecting and blocking a web attack includes a filter unit receiving web request data from a user terminal, and controlling a web application to maintain a standby state, and a web firewall daemon receiving the web request data from the filter unit and determining a risk by analyzing the web request data and transmitting the resulting risk to the filtering unit. A method of detecting and blocking a web attack includes receiving web request data from a user terminal, controlling a web application to maintain a standby state, transmitting the web request data to a web firewall daemon, determining a risk by analyzing the web request data, and transmitting the risk of the web request data to the filtering unit. Embodiments of the present invention can provide customer customized web security service without affecting the stability and the availability of the web application.