Host Route Injection for Network Security and Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IP forwarding mechanisms in data networks are vulnerable to attacks like spoofing and denial of service, and the configuration of routers and routing protocols is complex, making them difficult to manage effectively.

Innovation Solution

A method and system that detect data traffic in a forwarding domain, inject a host route associated with the detected traffic, and update a forwarding table, allowing for comparison of host paths to subnet route paths and installation of the host route when they do not match, thereby enhancing security and simplifying routing configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP forwarding devices such as routers are used to block attacks, then security against spoofing and denial of service attacks is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables forwarding devices to automatically detect data traffic and inject host routes into the routing table without requiring manual configuration. The device monitors its own forwarding decisions and autonomously updates routing information, eliminating the need for complex manual routing configuration while maintaining security through automatic attack prevention

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback mechanism where the forwarding device continuously monitors data traffic patterns and uses this information to dynamically update routing tables. By feeding back traffic detection results into the routing decision process, the system automatically adapts to network conditions and prevents attacks without requiring complex static configuration

Inventive Principle:
Principle #23Feedback

2Reliability

If manual routing configuration is performed, then control over routing paths is improved, but ease of operation deteriorates

Engineering Contradiction:
Improverouting controlVSAvoidconfiguration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The forwarding device performs self-configuration by automatically detecting data traffic patterns and injecting appropriate host routes into the routing table. This self-service approach eliminates the need for manual routing configuration while maintaining reliable routing control, as the device autonomously determines optimal paths based on actual traffic observations

Inventive Principle:
Principle #25Self-service

3Productivity

If host routes are injected based on detected traffic, then routing efficiency is improved, but measurement precision requirements increase

Engineering Contradiction:
Improverouting efficiencyVSAvoidtraffic detection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system injects host routes based on detected data traffic patterns without requiring absolute precision in traffic measurement. By using partial observation of traffic flows and injecting routes proactively, the system achieves efficient routing while tolerating reasonable measurement imprecision, avoiding the need for highly precise traffic analysis

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7822027B2Network routing to the socket
Publication Date: 2010.10.26 CISCO TECHNOLOGY INC
  • US7822027B2 patent drawing
  • US7822027B2 patent drawing
  • US7822027B2 patent drawing

AI summary

In one embodiment, detecting data traffic from a host device in a data forwarding domain, injecting a host route associated with the detected data traffic, and updating a forwarding table associated with the host route are provided.