ARP Request Rate Filtering via Layer 2 Sampling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virus throttling methods require layer 3 routing and virtual local area networking to be enabled for connection-rate filtering, which is not always necessary or efficient, and do not effectively monitor ARP requests to detect suspicious behavior in hosts within a subnet.
Innovation Solution
Implementing a network device with sampling circuitry to monitor and copy ARP request packets, determining the rate of ARP requests sent by hosts, and using an agent program to flag potentially malicious behavior without relying on route tables or layer 3 routing, allowing for connection-rate filtering within a subnet.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If layer 3 routing and virtual local area networking are enabled for connection-rate filtering, then virus throttling capability is provided, but device complexity and configuration requirements increase
Solution Approach 1:
The patent extracts the essential virus throttling function from the complex layer 3 routing infrastructure by monitoring ARP requests at layer 2. This allows the core functionality of detecting and throttling malicious connection rates to be separated from the unnecessary routing and virtual LAN configuration, reducing device complexity while maintaining security effectiveness
Solution Approach 2:
The network device is enhanced to perform both traditional switching functions and virus throttling monitoring through a unified ARP request analysis mechanism. The agent program and sampling circuitry provide multi-functionality by simultaneously supporting standard network operations and security monitoring without requiring separate routing infrastructure
2Measurement precision
If ARP request monitoring is implemented without layer 3 routing, then monitoring precision improves, but detection capability may be insufficient
Solution Approach 1:
The system implements feedback by continuously monitoring ARP request rates and comparing them against threshold values. When the rate exceeds the threshold, the system provides feedback by throttling the connection, creating a closed-loop control system that automatically responds to detected malicious behavior. This feedback mechanism enhances detection capability without requiring complex layer 3 routing analysis
Solution Approach 2:
The patent introduces an agent program as an intermediary between the sampling circuitry and the connection throttling mechanism. This agent analyzes ARP request patterns and determines whether throttling should be applied, serving as a mediator that simplifies the detection process while maintaining accurate identification of malicious behavior through standardized analysis criteria
Data Source
AI summary
One embodiment relates to a method of connection-rate filtering by a network device. Address resolution protocol (ARP) request packets received from a sub-network are monitored, and a copy of the received ARP request packets are sent to an agent program. The agent program determines a rate of ARP request packets sent by a host in the sub-network. Other embodiments are also disclosed.


