EENIC FPGA Interception for Host Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security architectures, particularly in enterprise environments, are vulnerable to advanced persistent threats as upper hierarchical level security systems fail to effectively monitor, collect, and control lower level enclave security activities, allowing exploits like malware and botnets to persist and propagate within and across lower level enclaves, often bypassing upper level security appliances.
Innovation Solution
An Enhanced Ethernet Network Interface Card (EENIC) is introduced, featuring a Field Programmable Array (FPGA), an internal Network Interface Controller (NIC), and a Peripheral Component Interconnect Express (PCIe) controller, which intercepts data undetected by the host or network, enabling independent security actions and operating modes such as Active Host Embedded (AHE) to monitor and control network data flows without relying on the host operating system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If host-based security software is used to monitor and protect computers, then security monitoring capability is provided, but the security defenses can be easily modified or disabled by exploitation code
Solution Approach 1:
The patent introduces a network interface card as an intermediary device between the network and the host system. This NIC performs security monitoring and data interception functions independently of the host operating system, preventing exploitation code from disabling security defenses. The NIC acts as a mediator that can inspect and control network traffic without being subject to host-based attacks.
Solution Approach 2:
The patent segments the security monitoring function from the host system by implementing it in the network interface card. This separation isolates the security monitoring capability from exploitation code that targets the host operating system, allowing independent operation and preventing modification or disablement of security defenses through host-based attacks.
2Ease of operation
If upper hierarchical level security systems are deployed to control network security, then centralized security management is achieved, but these systems fail to effectively monitor and control lower level enclave security activities
Solution Approach 1:
The patent implements a feedback mechanism where the network interface card captures and reports security-relevant data from lower level enclave activities back to upper hierarchical security systems. This feedback loop enables centralized security management to effectively monitor and control lower level activities by providing visibility into previously hidden security events and network traffic.
3Reliability
If network security components are positioned at various hierarchical points to implement defense in depth, then layered security protection is provided, but exploitation vectors within the enterprise emerge that bypass upper level security appliances
Solution Approach 1:
The network interface card serves as an intermediary that intercepts and inspects network traffic at the host level, preventing exploitation code from communicating with external systems or propagating within the enterprise. This intermediary position allows the NIC to block internal exploitation vectors that would otherwise bypass upper level security appliances by controlling network access at the host interface.
Data Source
AI summary
An Enhanced Ethernet Network Interface Card (EENIC) interfaces with a host and a network. The EENIC includes an internal network interface controller (NIC), a field programmable array (FPGA) in electrical communication with the internal network interface controller, and a peripheral component interconnect express (PCIe) controller, in independent electrical communication with the field programmable array or the internal network interface controller. The FPGA is configured to intercept data from either the host, or from the network, or from a combination thereof. Additionally, the configured interception is undetected by the host, or by the network, or a combination thereof.


