Campus Network Security Detection Device for Malicious Traffic Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current campus network defense systems are inadequate in blocking malicious traffic, as they rely solely on access-layer checkpoints, leading to weak defense performance and the spread of malicious traffic within the network.

Innovation Solution

A network defense method that utilizes multiple network devices across the campus network to determine whether to perform or forward security checks on packets, leveraging the capabilities of various devices to prevent malicious traffic spread and enhance security defense performance, including the use of check flags and specified fields to indicate completed security checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a checking point is deployed only on the access side of the campus network, then the device complexity is reduced, but the security defense performance deteriorates and malicious traffic cannot be effectively blocked

Engineering Contradiction:
Improvesecurity defense performanceVSAvoidnetwork device distribution
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security checking function across multiple network devices (access switches, aggregation switches, core switches) rather than concentrating it at a single access-side checking point. Each device performs security checking for packets passing through it, dividing the overall security defense into multiple independent segments that work together to block malicious traffic effectively.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extends security checking from a single access layer dimension to multiple network layers (access, aggregation, and core layers). This dimensional expansion ensures that security checking occurs at various points throughout the network hierarchy, preventing malicious traffic from spreading internally while maintaining manageable complexity through layered architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multiple network devices perform security checking, then the security defense performance improves, but the device complexity and processing load increase

Engineering Contradiction:
Improvesecurity checking effectivenessVSAvoidsecurity checking capability distribution
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by enabling each network device to perform security checking based on its specific capabilities and position in the network. Access switches check for basic security policies, aggregation switches perform more comprehensive inspection, and core switches handle high-volume traffic. Each device's checking depth and type are tailored to its local role, optimizing overall effectiveness while managing individual device complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If security checking is performed on all packets, then the security coverage improves, but the processing speed and network throughput deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoidpacket processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies partial action by performing security checking selectively rather than uniformly on all packets. Devices can skip checking for packets that have already been validated at previous layers, or for traffic matching known safe patterns. This selective approach maintains comprehensive security coverage while significantly improving processing speed by avoiding redundant checking operations.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent ensures continuity of useful action by maintaining security checking for packets that pass through multiple devices, ensuring that security validation continues throughout the packet's journey across the network. This prevents security gaps while optimizing performance through coordinated checking across access, aggregation, and core layers.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP3905634B1Network defense method and security detection device
Publication Date: 2023.12.20 HUAWEI TECH CO LTD
  • EP3905634B1 patent drawingFigure 1
  • EP3905634B1 patent drawingFigure 2~3
  • EP3905634B1 patent drawingFigure 4

AI summary

The field of communications technologies is related, and a network defense method and a security detection device are disclosed, to resolve a problem of malicious traffic spreading in a campus network. The method includes: A security detection device receives a first packet. The security detection device detects the first packet when security detection on the first packet is not completed and a security detection capability of the security detection device is sufficient to detect the first packet. Alternatively, the security detection device forwards the first packet when security detection on the first packet is not completed and a security detection capability of the security detection device is insufficient.