Host-Side Intrusion Blocking via Feedback Loop

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Contemporary intrusion and extrusion detection systems do not effectively prevent attacks by only implementing defense measures at the destination, such as firewalls or hosts, allowing offending hosts to continue launching attacks like Denial of Service (DoS) or Distributed DOS (DDoS), which overburden these systems with additional processing.

Innovation Solution

The method involves detecting intrusion attempts and sending blocking instructions back to the offending host, which verifies the packet's origin and inhibits further transmission based on an intrusion protection policy, potentially shutting down malicious applications or processes, and notifying operators through event logs or messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If defense measures are implemented only at the destination (firewalls or hosts), then intrusion detection capability is improved, but the offending host continues to launch attacks and overburdens the defense systems with additional processing

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidsystem processing capacity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements a feedback mechanism where the destination system sends blocking instructions back to the offending host upon detecting intrusions. This feedback loop enables the offending host to identify and stop its own malicious activities, resolving the contradiction by improving detection precision while reducing the processing burden on defense systems through automated host-side blocking actions

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables the offending host to service its own security problems by receiving blocking instructions and automatically inhibiting further transmission of offending packets. This self-service approach allows the host to stop its own attacks without requiring continuous intervention from external defense systems, thereby improving detection capability while preserving system processing capacity

Inventive Principle:
Principle #25Self-service

2Reliability

If blocking instructions are sent back to the offending host to inhibit further transmission, then network security is improved, but additional verification and processing steps are required at the offending host

Engineering Contradiction:
Improvenetwork securityVSAvoidhost processing steps
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having the offending host verify the origin of blocking instructions before executing blocking operations. This preliminary verification step ensures security reliability while maintaining relatively simple processing by using straightforward origin verification mechanisms rather than complex analysis

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10033749B2Blocking intrusion attacks at an offending host
Publication Date: 2018.07.24 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10033749B2 patent drawing
  • US10033749B2 patent drawing
  • US10033749B2 patent drawing

AI summary

A method, apparatus, and program product are provided for protecting a network from intrusions. An offending packet communicated by an offending host coupled to a protected network is detected. In response to the detection, a blocking instruction is returned to the offending host to initiate an intrusion protection operation on the offending host, where the blocking instruction inhibits further transmission of offending packets by the offending host. At the offending host, a blocking instruction is received with a portion of an offending packet. The offending host verifies that the offending packet originated from the host. In response to the verification of the offending packet originating from the host, an intrusion protection operation is initiated on the host thereby inhibiting transmission of a subsequent outbound offending packet by the host.