Distributed Signature Update for Packet Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for packet-based networks are either fast but not adaptive to new attack patterns or adaptive but cause high processing load, and are concentrated on individual Session Border Controllers, failing to efficiently protect against various attacks across multiple layers.

Innovation Solution

A method and protection unit that performs signature analysis and anomaly detection using statistical analysis and machine learning algorithms, distributing updated signatures across security border nodes to adaptively address new attacks, reducing processing load and enhancing detection efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If classification based detection algorithms are used for adaptive security detection, then adaptability to new attack patterns is improved, but processing load increases significantly

Engineering Contradiction:
Improveadaptability to new attack patternsVSAvoidprocessing load
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent divides the security detection system into multiple security border nodes distributed across the network perimeter. Each node independently performs detection, segmenting the overall processing load. This allows the system to maintain adaptability through distributed classification algorithms while reducing the processing burden on any single node by parallelizing detection across multiple segments of the network boundary.

Inventive Principle:
Principle #1Segmentation

2Speed

If signature based detection is used for fast attack identification, then processing speed is improved, but adaptability to new attacks deteriorates

Engineering Contradiction:
Improveprocessing speedVSAvoidadaptability to new attack patterns
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by maintaining a distributed signature database across security border nodes that is continuously updated with new attack patterns. Before new attacks occur, the system pre-distributes updated signatures to all border nodes through a collaborative learning mechanism. This allows fast signature-based detection to remain effective while adapting to new threats in advance, resolving the contradiction between speed and adaptability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs feedback mechanisms where security border nodes share detection results and anomaly data across the network. When one node detects a new attack pattern or anomaly, this information is fed back to other nodes, which then update their local signature databases and detection models. This distributed feedback loop enables the system to maintain high processing speed through signature matching while simultaneously adapting to new attack patterns through continuous learning and signature updates.

Inventive Principle:
Principle #23Feedback

3Device complexity

If centralized security strategies are implemented on individual Session Border Controllers, then implementation simplicity is improved, but network-wide protection effectiveness deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidnetwork-wide protection effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements a universal security architecture where the same detection algorithms, signature databases, and anomaly detection mechanisms are deployed across multiple security border nodes throughout the network. Each node performs identical security functions locally, providing network-wide protection through replicated universal functionality. This maintains implementation simplicity through standardized deployment while achieving comprehensive network-wide effectiveness through distributed execution at multiple strategic points.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs a nested architecture where individual security border nodes contain complete detection capabilities (signatures, anomaly detectors, semantic processing), which are themselves nested within the broader network security framework. Each node is a self-contained security unit that can operate independently while contributing to the overall network security. This nested structure provides network-wide protection through multiple layers of distributed security nodes, each maintaining simplicity while collectively achieving comprehensive coverage.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentEP2112803B1Attack protection for a packet-based network
Publication Date: 2013.12.18 ALCATEL LUCENT SA
  • EP2112803B1 patent drawingFigure 1~2
  • EP2112803B1 patent drawingFigure 3~4
  • EP2112803B1 patent drawingFigure 5~6

AI summary

The invention relates to a protection unit (15) for protecting a packet-based network from attacks, comprising: a signature analyzer (5) for analyzing a packet stream (6) received in a security border node (2a) of the packet-based network (1) and for detecting attacks by comparing signatures of the packet stream (6) with a set of signatures of previously identified attacks, an anomaly detector, in particular a statistical analyzer (7), for detecting anomalies in the packet stream (6), and a signature interference unit (9) for updating the set of signatures when anomalies in the packet stream (6) are detected, the updated set of signatures (12) being subsequently used for performing the signature analysis. A distribution unit (13) distributes at least one signature of the updated set of signatures (12) to at least one further, preferably to each further security border node of the packet-based network (1). The invention also relates to a security border node comprising such a protection unit, to a network comprising at least two such protection units, and to a corresponding protection method.