Encapsulated Packet Inspection for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems face challenges in accurately detecting network attacks within encapsulated network traffic, as they struggle to differentiate between malicious and non-malicious packets within encapsulated sessions, often discarding entire packets that contain both malicious and non-malicious sub-packets.

Innovation Solution

An intrusion detection and prevention device (IDP) receives packet flows with encapsulated sessions, extracts and inspects individual sub-packets, identifies malicious sessions, and applies policy actions only to those determined malicious, reconstructing packets to exclude malicious sub-packets while forwarding non-malicious ones, thereby applying fine-grained policy actions and avoiding unnecessary packet discard.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional intrusion detection systems discard entire packets containing encapsulated sub-packets, then security detection coverage is improved, but network traffic loss increases and legitimate traffic is blocked

Engineering Contradiction:
Improvesecurity detection coverageVSAvoidnetwork traffic loss
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The system segments the packet processing into two independent stages: first extracting and inspecting encapsulated sub-packets for malicious content, then selectively discarding only the malicious sub-packets while preserving the legitimate outer packet and any non-malicious sub-packets. This segmentation allows security inspection without automatic wholesale packet rejection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system extracts the encapsulated sub-packets from the outer packet for separate inspection. By taking out the inner content for analysis and then selectively removing only the malicious portions, the system avoids discarding the entire outer packet structure and any legitimate traffic it may contain.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If intrusion detection systems apply pattern matching to detect attacks in encapsulated traffic, then attack detection capability is improved, but processing complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary extraction of encapsulated sub-packets from outer packets before applying pattern matching inspection. This preliminary action organizes the data structure in advance, making subsequent security inspection more efficient and manageable by working with discrete sub-packet units rather than complex nested structures.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If intrusion detection systems inspect all sub-packets in encapsulated packets, then detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system segments the inspection process to work with individual sub-packets extracted from outer packets. This segmentation enables parallel processing of multiple sub-packets and allows the system to stop inspecting once malicious content is found in any sub-packet, reducing overall processing time while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9398043B1Applying fine-grain policy action to encapsulated network attacks
Publication Date: 2016.07.19 JUNIPER NETWORKS INC
  • US9398043B1 patent drawing
  • US9398043B1 patent drawing
  • US9398043B1 patent drawing

AI summary

An intrusion detection system inspects encapsulated packet flows and, upon detecting a malicious encapsulated packet flow, may close an encapsulated network session corresponding to the malicious flow or drop sub-packets of the malicious flow without acting against non-malicious sub-packets and/or sessions. In one example, a network device includes a flow analysis module that receives a packet flow packets, each packet comprising a packet header and one or more sub-packets each corresponding to respective network sessions, an attack detection module that identifies at least one of the network sessions as a malicious network session, a policy action module that executes a policy action on the sub-packet corresponding to the malicious network session based on the identification of the malicious network session, and a forwarding component that forms a reconstructed packet comprising the packet header and the sub-packets excluding the sub-packet corresponding to the malicious network session and forwards the reconstructed packet.