Dynamic Network Switch Rule Structure for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Access Control Lists (ACLs) in networks are insufficiently precise and static, leading to false positives in detecting network anomalies, inability to dynamically respond to changing conditions, and limited effectiveness in mitigating network anomalies, often resulting in significant damage due to delayed responses.

Innovation Solution

An improved rule structure that incorporates usage-derived packet statistics, allowing for dynamic and precise detection and mitigation of network anomalies by specifying conditions based on cumulative packet counts, rates, and ratios, enabling dynamic responses through actions like packet mirroring, redirection, and rule reconfiguration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If static ACL rules are used to detect network anomalies, then the rule structure is simple and easy to implement, but the detection precision is insufficient and false positives occur frequently

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidrule structure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms static ACL rules into dynamic rules that automatically adjust their state based on real-time network conditions. Rules can transition between states (e.g., from monitor to block) based on detected anomaly patterns, enabling the system to adapt its detection and response behavior dynamically without requiring complex manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the results of anomaly detection and the current state of network traffic flow back into the rule evaluation process. This allows rules to modify their own behavior based on observed network conditions, improving detection precision by continuously learning from network patterns while maintaining manageable rule complexity through automated decision-making.

Inventive Principle:
Principle #23Feedback

2Speed

If static ACL rules always deny access to packets meeting specified profiles, then the response is immediate, but valid packets are incorrectly denied and network damage occurs due to lack of dynamic response

Engineering Contradiction:
Improveresponse speedVSAvoidpacket access accuracy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements dynamic rule states that can transition between different response modes (e.g., monitor, block, permit) based on real-time network conditions. This allows the system to respond immediately to detected anomalies by switching to block mode while automatically permitting valid traffic when anomaly conditions are not met, thus maintaining both fast response speed and high packet access accuracy.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameters of ACL rules dynamically based on network conditions. Rules can modify their action parameters (permit/deny/monitor) and threshold parameters based on observed traffic patterns, enabling immediate response to threats while avoiding false positives that would occur with static parameter settings.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If ACL rules mirror packets to administrators for examination, then the system can identify anomalies, but significant damage occurs during the latency period before response

Engineering Contradiction:
Improveanomaly identification accuracyVSAvoidresponse latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary actions where the system automatically blocks suspicious traffic based on pre-configured anomaly patterns and thresholds before administrators need to manually examine and respond. The system performs preliminary detection and automated response in the background, reducing response latency while maintaining accurate anomaly identification through continuous monitoring and pattern matching.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides self-service capabilities where ACL rules automatically detect, analyze, and respond to network anomalies without requiring constant administrator intervention. The automated rule engine performs anomaly identification and executes appropriate responses (block, permit, monitor) autonomously, eliminating the time loss associated with manual packet examination and response while maintaining high identification accuracy through sophisticated pattern recognition.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7668969B1Rule structure for performing network switch functions
Publication Date: 2010.02.23 EXTREME NETWORKS INC
  • US7668969B1 patent drawing
  • US7668969B1 patent drawing
  • US7668969B1 patent drawing

AI summary

One or more rules for performing one or more network switch functions, the one or more rules conforming to an improved rule structure, are provided. The improved rule structure comprises a first specification defining one or more conditions to be met, the one or more conditions comprising or including one or more conditions to be met by one or more usage-derived packet statistics, and a second specification defining one or more actions to be taken by the network switch if the one or more specified conditions are met.