Dynamic Data Socket Descriptor Mirroring for Security Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mirroring mechanisms in network switches lack intelligence to mirror packets based on application states without impacting other applications or application flows, making them ineffective for identifying threats in scaled-out, distributed applications.

Innovation Solution

A dynamic mirroring mechanism using data socket descriptors that allows applications to control mirroring actions such as allow-and-analyze, drop-and-analyze, and mirror, enabling precise and flexible packet mirroring at the data socket descriptor level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional flow-based mirroring is enabled at switch ports, then packet replication for debugging and traffic analysis is achieved, but performance impact occurs on all other applications and application flows

Engineering Contradiction:
Improvepacket mirroring capabilityVSAvoidapplication performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the mirroring function from global switch-port level to application-instance level using data socket descriptors. Each application instance can have its own mirrored data socket descriptors, allowing selective mirroring of only the necessary application flows without capturing all traffic at the switch level, thereby reducing the performance impact on other applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by enabling mirroring with different actions (allow-and-analyze, drop-and-analyze, mirror) at the level of individual data socket descriptors rather than uniformly across all flows. This allows precise control over which application flows are mirrored and what actions are taken, minimizing performance impact on non-mirrored flows while achieving the required security analytics.

Inventive Principle:
Principle #3Local quality

2Loss of information

If mirroring is performed at switch port level, then traffic pattern analysis is enabled, but application-level control over mirroring functionality is lost

Engineering Contradiction:
Improvetraffic analysis capabilityVSAvoidapplication control over mirroring
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent introduces data socket descriptors as an intermediary between the application layer and the mirroring mechanism. These descriptors serve as handles that applications can use to control mirroring of their specific data flows. The security analytics system can then attach mirroring actions to these descriptors, providing both application-level control and detailed traffic analysis capability without requiring switch-port level configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If current mirroring mechanisms are used for scaled-out distributed applications, then data theft detection is attempted, but effectiveness is reduced due to lack of intelligence about application states

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidapplication state awareness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic mirroring where the mirroring behavior adapts to application states. The system can dynamically attach different actions (allow-and-analyze, drop-and-analyze, mirror) to data socket descriptors based on the application's current state and security policies. This dynamic approach enables intelligent threat detection by responding to actual application behavior rather than applying static mirroring rules, improving reliability while maintaining adaptability to distributed application architectures.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10397277B2Dynamic data socket descriptor mirroring mechanism and use for security analytics
Publication Date: 2019.08.27 AVOCADO SYSTEMS INC
  • US10397277B2 patent drawing
  • US10397277B2 patent drawing
  • US10397277B2 patent drawing

AI summary

According to another embodiment, a system includes a processing circuit and logic integrated with and/or executable by the processing circuit. The logic is configured to cause the processing circuit to receive, at a first host on which an application instance is operating, an application or data security policy for a first data socket descriptor indicating to perform one or more actions including to mirror one or more payloads received or transmitted by the first data socket descriptor of the application instance. The logic is also configured to cause the processing circuit to perform, by the first host, at least one action selected from a group of actions in response to the indication by the application and data security policy to perform the one or more actions, the group of actions including allow-and-analyze, drop-and-analyze, and mirror.