Encapsulated Packet Inspection for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional intrusion detection systems face challenges in accurately detecting network attacks within encapsulated network traffic, as they struggle to differentiate between malicious and non-malicious packets within encapsulated sessions, often discarding entire packets that contain both malicious and non-malicious sub-packets.
Innovation Solution
An intrusion detection and prevention device (IDP) receives packet flows with encapsulated sessions, extracts and inspects individual sub-packets, identifies malicious sessions, and applies policy actions only to those determined malicious, reconstructing packets to exclude malicious sub-packets while forwarding non-malicious ones, thereby applying fine-grained policy actions and avoiding unnecessary packet discard.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional intrusion detection systems discard entire packets containing encapsulated sub-packets, then security detection coverage is improved, but network traffic loss increases and legitimate traffic is blocked
Solution Approach 1:
The system segments the packet processing into two independent stages: first extracting and inspecting encapsulated sub-packets for malicious content, then selectively discarding only the malicious sub-packets while preserving the legitimate outer packet and any non-malicious sub-packets. This segmentation allows security inspection without automatic wholesale packet rejection.
Solution Approach 2:
The system extracts the encapsulated sub-packets from the outer packet for separate inspection. By taking out the inner content for analysis and then selectively removing only the malicious portions, the system avoids discarding the entire outer packet structure and any legitimate traffic it may contain.
2Measurement precision
If intrusion detection systems apply pattern matching to detect attacks in encapsulated traffic, then attack detection capability is improved, but processing complexity increases
Solution Approach 1:
The system performs preliminary extraction of encapsulated sub-packets from outer packets before applying pattern matching inspection. This preliminary action organizes the data structure in advance, making subsequent security inspection more efficient and manageable by working with discrete sub-packet units rather than complex nested structures.
3Measurement precision
If intrusion detection systems inspect all sub-packets in encapsulated packets, then detection accuracy is improved, but processing time increases
Solution Approach 1:
The system segments the inspection process to work with individual sub-packets extracted from outer packets. This segmentation enables parallel processing of multiple sub-packets and allows the system to stop inspecting once malicious content is found in any sub-packet, reducing overall processing time while maintaining detection accuracy.
Data Source
AI summary
An intrusion detection system inspects encapsulated packet flows and, upon detecting a malicious encapsulated packet flow, may close an encapsulated network session corresponding to the malicious flow or drop sub-packets of the malicious flow without acting against non-malicious sub-packets and/or sessions. In one example, a network device includes a flow analysis module that receives a packet flow packets, each packet comprising a packet header and one or more sub-packets each corresponding to respective network sessions, an attack detection module that identifies at least one of the network sessions as a malicious network session, a policy action module that executes a policy action on the sub-packet corresponding to the malicious network session based on the identification of the malicious network session, and a forwarding component that forms a reconstructed packet comprising the packet header and the sub-packets excluding the sub-packet corresponding to the malicious network session and forwards the reconstructed packet.


