Ethernet Switch Attack Sensing With Heterogeneous Dual Controllers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for enhancing Ethernet switch security can only defend against known attack methods and vulnerabilities, failing to identify and counter unknown attacks or backdoors, as they rely on limited and outdated software resources.

Innovation Solution

A method and device utilizing a heterogeneous equivalent controller structure with a main and auxiliary controller, each with different CPUs, operating systems, and protocol stack software, to automatically sense attack behaviors by comparing response data and informing administrators of inconsistencies, ensuring effective identification and defense against unknown attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security methods (flow control, filtering, authentication) are used to enhance switch security, then known attack methods can be defended, but unknown attacks or backdoors cannot be identified

Engineering Contradiction:
Improvesecurity defense capabilityVSAvoidability to identify unknown attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The controller is divided into two independent segments: a main controller that handles normal data interaction and an auxiliary controller that operates in an invisible state. This segmentation allows the system to defend against attacks by isolating the auxiliary controller, which can detect unknown threats without being exposed to them, thus resolving the contradiction between defending known attacks and identifying unknown attacks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The auxiliary controller acts as an intermediary that indirectly monitors the system for attacks. It receives the same service requests as the main controller but processes them in isolation, comparing results to detect anomalies. This intermediary approach enables the system to identify unknown attacks without exposing the main controller to potential threats

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If antivirus software with attack identification function is installed on the switch, then attack identification capability is improved, but software resources are limited and difficult to update

Engineering Contradiction:
Improveattack identification capabilityVSAvoidsoftware resource constraints
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of installing antivirus software with limited resources, the system creates a copy of the controller's functionality in the auxiliary controller. This copy operates in parallel and can independently analyze service requests for attack patterns, effectively increasing the system's attack identification capability without the resource constraints of traditional antivirus software

Inventive Principle:
Principle #26Copying

3Measurement precision

If the auxiliary controller is isolated from the network switch in an invisible state, then attack detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidcontroller architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The auxiliary controller is designed with multi-functionality: it can process service requests, compare results with the main controller, detect attacks, and remain isolated when needed. This universal design allows the same component to serve multiple purposes, reducing overall system complexity despite the added detection capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11570202B2Method, device and ethernet switch for automatically sensing attack behaviors
Publication Date: 2023.01.31 THE PLA INFORMATION ENG UNIV
  • US11570202B2 patent drawing
  • US11570202B2 patent drawing
  • US11570202B2 patent drawing

AI summary

A method for automatically sensing attack behaviors, the method including: distributing a service request from a network switch to a response module, where the response module includes a main controller configured for data interaction processing and an auxiliary controller configured for interactive data processing; generating, by the main controller and the auxiliary controller in the response module, respective response data according to the service request, respectively; and comparing the respective response data of the main controller with the respective response data of the auxiliary controller; if a result of comparison is inconsistent, indicating the network switch is abnormal, an administrator is informed, and the response data generated by the auxiliary controller is fed back to the network switch; and, if the result of comparison is consistent, the response data generated by the main controller is fed back to the network switch.