ARP Request Rate Filtering via Layer 2 Sampling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virus throttling methods require layer 3 routing and virtual local area networking to be enabled for connection-rate filtering, which is not always necessary or efficient, and do not effectively monitor ARP requests to detect suspicious behavior in hosts within a subnet.

Innovation Solution

Implementing a network device with sampling circuitry to monitor and copy ARP request packets, determining the rate of ARP requests sent by hosts, and using an agent program to flag potentially malicious behavior without relying on route tables or layer 3 routing, allowing for connection-rate filtering within a subnet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If layer 3 routing and virtual local area networking are enabled for connection-rate filtering, then virus throttling capability is provided, but device complexity and configuration requirements increase

Engineering Contradiction:
Improvevirus throttling capabilityVSAvoidrouting and networking configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential virus throttling function from the complex layer 3 routing infrastructure by monitoring ARP requests at layer 2. This allows the core functionality of detecting and throttling malicious connection rates to be separated from the unnecessary routing and virtual LAN configuration, reducing device complexity while maintaining security effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network device is enhanced to perform both traditional switching functions and virus throttling monitoring through a unified ARP request analysis mechanism. The agent program and sampling circuitry provide multi-functionality by simultaneously supporting standard network operations and security monitoring without requiring separate routing infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If ARP request monitoring is implemented without layer 3 routing, then monitoring precision improves, but detection capability may be insufficient

Engineering Contradiction:
ImproveARP request rate detectionVSAvoidmalicious behavior identification
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements feedback by continuously monitoring ARP request rates and comparing them against threshold values. When the rate exceeds the threshold, the system provides feedback by throttling the connection, creating a closed-loop control system that automatically responds to detected malicious behavior. This feedback mechanism enhances detection capability without requiring complex layer 3 routing analysis

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an agent program as an intermediary between the sampling circuitry and the connection throttling mechanism. This agent analyzes ARP request patterns and determines whether throttling should be applied, serving as a mediator that simplifies the detection process while maintaining accurate identification of malicious behavior through standardized analysis criteria

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8510833B2Connection-rate filtering using ARP requests
Publication Date: 2013.08.13 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8510833B2 patent drawing
  • US8510833B2 patent drawing
  • US8510833B2 patent drawing

AI summary

One embodiment relates to a method of connection-rate filtering by a network device. Address resolution protocol (ARP) request packets received from a sub-network are monitored, and a copy of the received ARP request packets are sent to an agent program. The agent program determines a rate of ARP request packets sent by a host in the sub-network. Other embodiments are also disclosed.