EENIC FPGA Interception for Host Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security architectures, particularly in enterprise environments, are vulnerable to advanced persistent threats as upper hierarchical level security systems fail to effectively monitor, collect, and control lower level enclave security activities, allowing exploits like malware and botnets to persist and propagate within and across lower level enclaves, often bypassing upper level security appliances.

Innovation Solution

An Enhanced Ethernet Network Interface Card (EENIC) is introduced, featuring a Field Programmable Array (FPGA), an internal Network Interface Controller (NIC), and a Peripheral Component Interconnect Express (PCIe) controller, which intercepts data undetected by the host or network, enabling independent security actions and operating modes such as Active Host Embedded (AHE) to monitor and control network data flows without relying on the host operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host-based security software is used to monitor and protect computers, then security monitoring capability is provided, but the security defenses can be easily modified or disabled by exploitation code

Engineering Contradiction:
Improvesecurity monitoring reliabilityVSAvoidvulnerability to exploitation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network interface card as an intermediary device between the network and the host system. This NIC performs security monitoring and data interception functions independently of the host operating system, preventing exploitation code from disabling security defenses. The NIC acts as a mediator that can inspect and control network traffic without being subject to host-based attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security monitoring function from the host system by implementing it in the network interface card. This separation isolates the security monitoring capability from exploitation code that targets the host operating system, allowing independent operation and preventing modification or disablement of security defenses through host-based attacks.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If upper hierarchical level security systems are deployed to control network security, then centralized security management is achieved, but these systems fail to effectively monitor and control lower level enclave security activities

Engineering Contradiction:
Improvecentralized security managementVSAvoidsecurity activity visibility
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the network interface card captures and reports security-relevant data from lower level enclave activities back to upper hierarchical security systems. This feedback loop enables centralized security management to effectively monitor and control lower level activities by providing visibility into previously hidden security events and network traffic.

Inventive Principle:
Principle #23Feedback

3Reliability

If network security components are positioned at various hierarchical points to implement defense in depth, then layered security protection is provided, but exploitation vectors within the enterprise emerge that bypass upper level security appliances

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidinternal exploitation vectors
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The network interface card serves as an intermediary that intercepts and inspects network traffic at the host level, preventing exploitation code from communicating with external systems or propagating within the enterprise. This intermediary position allows the NIC to block internal exploitation vectors that would otherwise bypass upper level security appliances by controlling network access at the host interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10104096B1Host-based, network enabled, integrated remote interrogation system
Publication Date: 2018.10.16 THE GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE SECRETARY OF THE AIR FORCE
  • US10104096B1 patent drawing
  • US10104096B1 patent drawing
  • US10104096B1 patent drawing

AI summary

An Enhanced Ethernet Network Interface Card (EENIC) interfaces with a host and a network. The EENIC includes an internal network interface controller (NIC), a field programmable array (FPGA) in electrical communication with the internal network interface controller, and a peripheral component interconnect express (PCIe) controller, in independent electrical communication with the field programmable array or the internal network interface controller. The FPGA is configured to intercept data from either the host, or from the network, or from a combination thereof. Additionally, the configured interception is undetected by the host, or by the network, or a combination thereof.