Network Gateway MPDU Dissection for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional gateways discard valuable network protocol data when transitioning between connection-based and connectionless networks, leading to inefficiencies and vulnerabilities in data communication, particularly in preventing denial of service attacks and optimizing network resource usage.

Innovation Solution

The WaGER system dissects MPDUs to collect and analyze network protocol data across various layers, applying rule-based responses to manage data flow, filter malicious traffic, and optimize resource allocation, thereby enhancing network security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If conventional gateways discard network protocol data during MPDU disaggregation, then device complexity is reduced, but network security and traffic management capability deteriorate

Engineering Contradiction:
Improvegateway processing complexityVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent extracts and retains specific network protocol data fields from the MPDU that are relevant for security analysis and traffic management, while discarding unnecessary data. This selective extraction maintains security capabilities without requiring the gateway to process and store all protocol data, thus resolving the contradiction between device complexity and network security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different processing qualities to different parts of the protocol data structure. Critical security-related fields are preserved and analyzed in detail, while non-critical fields are discarded or processed minimally. This local differentiation maintains security reliability without uniformly increasing gateway complexity across all data processing operations.

Inventive Principle:
Principle #3Local quality

2Speed

If conventional gateways discard network protocol data, then data transmission speed is improved, but ability to detect and prevent denial of service attacks deteriorates

Engineering Contradiction:
Improvedata transmission speedVSAvoidattack detection capability
Core Design Contradiction:
SpeedVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary analysis of network protocol data during the MPDU disaggregation process itself, before the data is discarded. By extracting and analyzing critical fields at this early stage, the system can detect potential denial of service attacks without requiring additional processing time later, thus maintaining data transmission speed while improving attack detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary analysis layer that processes only the essential protocol data fields needed for security detection. This intermediary layer acts as a mediator between the high-speed data transmission path and the security analysis function, allowing fast transmission to continue while enabling effective attack detection through selective data examination.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If conventional gateways perform no protocol data analysis, then productivity is improved, but network resource optimization capability deteriorates

Engineering Contradiction:
Improvegateway processing throughputVSAvoidnetwork resource optimization
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent applies partial action by performing analysis only on the specific protocol data fields that are most relevant for network resource optimization, rather than analyzing all protocol data. This selective partial analysis maintains high gateway processing throughput while providing sufficient information for effective network resource optimization and traffic management decisions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8265089B2Network gateway with enhanced requesting
Publication Date: 2012.09.11 TOUCHPOINT PROJECTION INNOVATIONS LLC
  • US8265089B2 patent drawing
  • US8265089B2 patent drawing
  • US8265089B2 patent drawing

AI summary

A gateway and/or software for running on a gateway that communicates data units from a connection based network to a connectionless network, where the gateway uses at least some network protocol data from the connection based network in checking against a set of rules to determine whether some responsive reaction is appropriate. Preferably, the network protocol data from the connection based network is low level network protocol data (that is, physical layer and/or data link layer) that would otherwise be discarded by the gateway as the data was de-encapsulated and sent along to the receiving, connectionless network. Some possible responsive reactions include: selectively blocking data communication; slowing down selected data communications; sending responsive communications back to selected data sending machines; and/or alerting of network administrator(s).