Host-Side Intrusion Blocking via Feedback Loop
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contemporary intrusion and extrusion detection systems do not effectively prevent attacks by only implementing defense measures at the destination, such as firewalls or hosts, allowing offending hosts to continue launching attacks like Denial of Service (DoS) or Distributed DOS (DDoS), which overburden these systems with additional processing.
Innovation Solution
The method involves detecting intrusion attempts and sending blocking instructions back to the offending host, which verifies the packet's origin and inhibits further transmission based on an intrusion protection policy, potentially shutting down malicious applications or processes, and notifying operators through event logs or messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If defense measures are implemented only at the destination (firewalls or hosts), then intrusion detection capability is improved, but the offending host continues to launch attacks and overburdens the defense systems with additional processing
Solution Approach 1:
The patent implements a feedback mechanism where the destination system sends blocking instructions back to the offending host upon detecting intrusions. This feedback loop enables the offending host to identify and stop its own malicious activities, resolving the contradiction by improving detection precision while reducing the processing burden on defense systems through automated host-side blocking actions
Solution Approach 2:
The patent enables the offending host to service its own security problems by receiving blocking instructions and automatically inhibiting further transmission of offending packets. This self-service approach allows the host to stop its own attacks without requiring continuous intervention from external defense systems, thereby improving detection capability while preserving system processing capacity
2Reliability
If blocking instructions are sent back to the offending host to inhibit further transmission, then network security is improved, but additional verification and processing steps are required at the offending host
Solution Approach 1:
The patent implements preliminary action by having the offending host verify the origin of blocking instructions before executing blocking operations. This preliminary verification step ensures security reliability while maintaining relatively simple processing by using straightforward origin verification mechanisms rather than complex analysis
Data Source
AI summary
A method, apparatus, and program product are provided for protecting a network from intrusions. An offending packet communicated by an offending host coupled to a protected network is detected. In response to the detection, a blocking instruction is returned to the offending host to initiate an intrusion protection operation on the offending host, where the blocking instruction inhibits further transmission of offending packets by the offending host. At the offending host, a blocking instruction is received with a portion of an offending packet. The offending host verifies that the offending packet originated from the host. In response to the verification of the offending packet originating from the host, an intrusion protection operation is initiated on the host thereby inhibiting transmission of a subsequent outbound offending packet by the host.


