Dynamic Network Switch Rule Structure for Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Access Control Lists (ACLs) in networks are insufficiently precise and static, leading to false positives in detecting network anomalies, inability to dynamically respond to changing conditions, and limited effectiveness in mitigating network anomalies, often resulting in significant damage due to delayed responses.
Innovation Solution
An improved rule structure that incorporates usage-derived packet statistics, allowing for dynamic and precise detection and mitigation of network anomalies by specifying conditions based on cumulative packet counts, rates, and ratios, enabling dynamic responses through actions like packet mirroring, redirection, and rule reconfiguration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If static ACL rules are used to detect network anomalies, then the rule structure is simple and easy to implement, but the detection precision is insufficient and false positives occur frequently
Solution Approach 1:
The patent transforms static ACL rules into dynamic rules that automatically adjust their state based on real-time network conditions. Rules can transition between states (e.g., from monitor to block) based on detected anomaly patterns, enabling the system to adapt its detection and response behavior dynamically without requiring complex manual reconfiguration.
Solution Approach 2:
The system implements feedback mechanisms where the results of anomaly detection and the current state of network traffic flow back into the rule evaluation process. This allows rules to modify their own behavior based on observed network conditions, improving detection precision by continuously learning from network patterns while maintaining manageable rule complexity through automated decision-making.
2Speed
If static ACL rules always deny access to packets meeting specified profiles, then the response is immediate, but valid packets are incorrectly denied and network damage occurs due to lack of dynamic response
Solution Approach 1:
The patent implements dynamic rule states that can transition between different response modes (e.g., monitor, block, permit) based on real-time network conditions. This allows the system to respond immediately to detected anomalies by switching to block mode while automatically permitting valid traffic when anomaly conditions are not met, thus maintaining both fast response speed and high packet access accuracy.
Solution Approach 2:
The system changes the operational parameters of ACL rules dynamically based on network conditions. Rules can modify their action parameters (permit/deny/monitor) and threshold parameters based on observed traffic patterns, enabling immediate response to threats while avoiding false positives that would occur with static parameter settings.
3Measurement precision
If ACL rules mirror packets to administrators for examination, then the system can identify anomalies, but significant damage occurs during the latency period before response
Solution Approach 1:
The patent implements preliminary actions where the system automatically blocks suspicious traffic based on pre-configured anomaly patterns and thresholds before administrators need to manually examine and respond. The system performs preliminary detection and automated response in the background, reducing response latency while maintaining accurate anomaly identification through continuous monitoring and pattern matching.
Solution Approach 2:
The system provides self-service capabilities where ACL rules automatically detect, analyze, and respond to network anomalies without requiring constant administrator intervention. The automated rule engine performs anomaly identification and executes appropriate responses (block, permit, monitor) autonomously, eliminating the time loss associated with manual packet examination and response while maintaining high identification accuracy through sophisticated pattern recognition.
Data Source
AI summary
One or more rules for performing one or more network switch functions, the one or more rules conforming to an improved rule structure, are provided. The improved rule structure comprises a first specification defining one or more conditions to be met, the one or more conditions comprising or including one or more conditions to be met by one or more usage-derived packet statistics, and a second specification defining one or more actions to be taken by the network switch if the one or more specified conditions are met.


