Network Gateway MPDU Dissection for Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional gateways discard valuable network protocol data when transitioning between connection-based and connectionless networks, leading to inefficiencies and vulnerabilities in data communication, particularly in preventing denial of service attacks and optimizing network resource usage.
Innovation Solution
The WaGER system dissects MPDUs to collect and analyze network protocol data across various layers, applying rule-based responses to manage data flow, filter malicious traffic, and optimize resource allocation, thereby enhancing network security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If conventional gateways discard network protocol data during MPDU disaggregation, then device complexity is reduced, but network security and traffic management capability deteriorate
Solution Approach 1:
The patent extracts and retains specific network protocol data fields from the MPDU that are relevant for security analysis and traffic management, while discarding unnecessary data. This selective extraction maintains security capabilities without requiring the gateway to process and store all protocol data, thus resolving the contradiction between device complexity and network security.
Solution Approach 2:
The patent applies different processing qualities to different parts of the protocol data structure. Critical security-related fields are preserved and analyzed in detail, while non-critical fields are discarded or processed minimally. This local differentiation maintains security reliability without uniformly increasing gateway complexity across all data processing operations.
2Speed
If conventional gateways discard network protocol data, then data transmission speed is improved, but ability to detect and prevent denial of service attacks deteriorates
Solution Approach 1:
The patent performs preliminary analysis of network protocol data during the MPDU disaggregation process itself, before the data is discarded. By extracting and analyzing critical fields at this early stage, the system can detect potential denial of service attacks without requiring additional processing time later, thus maintaining data transmission speed while improving attack detection capability.
Solution Approach 2:
The patent introduces an intermediary analysis layer that processes only the essential protocol data fields needed for security detection. This intermediary layer acts as a mediator between the high-speed data transmission path and the security analysis function, allowing fast transmission to continue while enabling effective attack detection through selective data examination.
3Productivity
If conventional gateways perform no protocol data analysis, then productivity is improved, but network resource optimization capability deteriorates
Solution Approach 1:
The patent applies partial action by performing analysis only on the specific protocol data fields that are most relevant for network resource optimization, rather than analyzing all protocol data. This selective partial analysis maintains high gateway processing throughput while providing sufficient information for effective network resource optimization and traffic management decisions.
Data Source
AI summary
A gateway and/or software for running on a gateway that communicates data units from a connection based network to a connectionless network, where the gateway uses at least some network protocol data from the connection based network in checking against a set of rules to determine whether some responsive reaction is appropriate. Preferably, the network protocol data from the connection based network is low level network protocol data (that is, physical layer and/or data link layer) that would otherwise be discarded by the gateway as the data was de-encapsulated and sent along to the receiving, connectionless network. Some possible responsive reactions include: selectively blocking data communication; slowing down selected data communications; sending responsive communications back to selected data sending machines; and/or alerting of network administrator(s).


