Web Firewall Daemon for Intelligent Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods fail to effectively detect and block intelligent web attacks without affecting web application stability or availability, and they require changes in IP and DNS information, which can lead to communication delays and increased costs, especially in cloud environments.
Innovation Solution
A system comprising a filter unit and a web firewall daemon that analyzes web request data to determine risks, modifies data as necessary, and transmits modified data, while maintaining existing network configurations and preventing SSL authentication exposure, all while being cost-effective and adaptable to cloud environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional firewalls and intrusion detection systems are used to detect web attacks, then basic security is provided, but they cannot effectively handle intelligent attack methods that continuously discover and attack function-specific vulnerabilities
Solution Approach 1:
The patent changes the detection parameters from general network traffic analysis to specific web application behavior analysis. The web firewall daemon analyzes HTTP request parameters, URL patterns, and application-level protocols to detect intelligent attacks that evade conventional firewalls focused on lower-level network parameters.
Solution Approach 2:
The patent introduces a web firewall daemon as an intermediary component between the web server and external requests. This daemon specifically handles web application protocol analysis and attack detection, bridging the gap between conventional firewalls and application-specific security needs without affecting overall system stability.
2Reliability
If web security services are implemented using conventional methods, then attack protection is provided, but web application stability and availability are affected
Solution Approach 1:
The patent segments the security function into a separate web firewall daemon process that operates independently from the web application server. This segmentation allows security scanning and attack detection to occur in parallel without blocking or destabilizing the main application, maintaining both security and stability simultaneously.
3Reliability
If IP and DNS information are changed to provide web firewall services, then security service is provided, but communication delays occur and initial costs increase
Solution Approach 1:
The patent implements a self-service web firewall daemon that runs locally on the web server system rather than requiring external firewall services. This eliminates the need to change IP and DNS information, avoiding communication delays with external services while providing comprehensive security protection.
4Reliability
If SSL authentication and personal keys are uploaded to web firewall service providers, then HTTPS security is provided, but SSL authentication and personal keys are exposed and initial cost increases
Solution Approach 1:
The patent extracts the SSL/TLS decryption and analysis capability into the local web firewall daemon, allowing inspection of encrypted traffic without exposing private keys to external service providers. The daemon can analyze HTTPS requests locally, eliminating the security risk of key exposure while maintaining encryption security.
Data Source
AI summary
A system for detecting and blocking a web attack includes a filter unit receiving web request data from a user terminal, and controlling a web application to maintain a standby state, and a web firewall daemon receiving the web request data from the filter unit and determining a risk by analyzing the web request data and transmitting the resulting risk to the filtering unit. A method of detecting and blocking a web attack includes receiving web request data from a user terminal, controlling a web application to maintain a standby state, transmitting the web request data to a web firewall daemon, determining a risk by analyzing the web request data, and transmitting the risk of the web request data to the filtering unit. Embodiments of the present invention can provide customer customized web security service without affecting the stability and the availability of the web application.

