Dynamic Data Socket Descriptor Mirroring for Security Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mirroring mechanisms in network switches lack intelligence to mirror packets based on application states without impacting other applications or application flows, making them ineffective for identifying threats in scaled-out, distributed applications.
Innovation Solution
A dynamic mirroring mechanism using data socket descriptors that allows applications to control mirroring actions such as allow-and-analyze, drop-and-analyze, and mirror, enabling precise and flexible packet mirroring at the data socket descriptor level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional flow-based mirroring is enabled at switch ports, then packet replication for debugging and traffic analysis is achieved, but performance impact occurs on all other applications and application flows
Solution Approach 1:
The patent segments the mirroring function from global switch-port level to application-instance level using data socket descriptors. Each application instance can have its own mirrored data socket descriptors, allowing selective mirroring of only the necessary application flows without capturing all traffic at the switch level, thereby reducing the performance impact on other applications.
Solution Approach 2:
The patent applies local quality by enabling mirroring with different actions (allow-and-analyze, drop-and-analyze, mirror) at the level of individual data socket descriptors rather than uniformly across all flows. This allows precise control over which application flows are mirrored and what actions are taken, minimizing performance impact on non-mirrored flows while achieving the required security analytics.
2Loss of information
If mirroring is performed at switch port level, then traffic pattern analysis is enabled, but application-level control over mirroring functionality is lost
Solution Approach 1:
The patent introduces data socket descriptors as an intermediary between the application layer and the mirroring mechanism. These descriptors serve as handles that applications can use to control mirroring of their specific data flows. The security analytics system can then attach mirroring actions to these descriptors, providing both application-level control and detailed traffic analysis capability without requiring switch-port level configuration.
3Reliability
If current mirroring mechanisms are used for scaled-out distributed applications, then data theft detection is attempted, but effectiveness is reduced due to lack of intelligence about application states
Solution Approach 1:
The patent implements dynamic mirroring where the mirroring behavior adapts to application states. The system can dynamically attach different actions (allow-and-analyze, drop-and-analyze, mirror) to data socket descriptors based on the application's current state and security policies. This dynamic approach enables intelligent threat detection by responding to actual application behavior rather than applying static mirroring rules, improving reliability while maintaining adaptability to distributed application architectures.
Data Source
AI summary
According to another embodiment, a system includes a processing circuit and logic integrated with and/or executable by the processing circuit. The logic is configured to cause the processing circuit to receive, at a first host on which an application instance is operating, an application or data security policy for a first data socket descriptor indicating to perform one or more actions including to mirror one or more payloads received or transmitted by the first data socket descriptor of the application instance. The logic is also configured to cause the processing circuit to perform, by the first host, at least one action selected from a group of actions in response to the indication by the application and data security policy to perform the one or more actions, the group of actions including allow-and-analyze, drop-and-analyze, and mirror.


