Delegating Host Security Filtering to Network Switches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security measures, such as firewalls and RADIUS servers, are inadequate in providing real-time, host device-specific threat filtering, as they often rely on generalized threat detection rules and resource-intensive software applications, which can be overwhelmed during attacks like denial-of-service (DOS) scenarios.
Innovation Solution
A method where host devices dynamically generate and enforce security-based filtering parameters with network devices, such as switches, to restrict traffic and isolate threats, leveraging access control lists (ACLs) and offloading filtering tasks from host devices to network switches for improved performance and specificity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If filtering is performed at the host device using a personal firewall, then host-specific threat filtering is achieved, but resource consumption increases significantly
Solution Approach 1:
The patent extracts the filtering function from the host device and relocates it to the network switch. The host device generates filtering parameters locally, but the actual traffic filtering is performed by the network switch, thereby reducing host resource consumption while maintaining host-specific filtering capability.
Solution Approach 2:
The network switch acts as an intermediary between the host device and the network traffic. It receives filtering parameters from the host device and enforces them by analyzing and filtering traffic, thereby offloading the resource-intensive filtering task from the host device.
2Adaptability or versatility
If generalized threat detection rules are used to handle multiple sampling streams, then network-wide security coverage is improved, but host device-specific protection is reduced
Solution Approach 1:
The patent segments the security function into two parts: network-wide security policies are enforced by the network switch, while host-specific filtering parameters are generated by the host device. This segmentation allows both network-wide coverage and host-specific protection to coexist effectively.
Solution Approach 2:
The host device generates filtering parameters locally based on its specific security needs and threat detection, while the network switch enforces these parameters. This local quality approach ensures that each host receives customized security filtering tailored to its specific requirements while still benefiting from network-wide security coverage.
3Speed
If real-time filtering parameters are applied dynamically, then response time to threats is improved, but system complexity increases
Solution Approach 1:
The host device autonomously generates and updates filtering parameters in real-time based on its security needs and detected threats. This self-service capability allows dynamic response to threats without requiring complex centralized control, thereby improving response speed while managing system complexity.
Data Source
AI summary
A method for applying a host security service to a network is described herein. The network may include a host device and a network device. The network device may receive a request for security-based filtering. The request includes filtering parameters that restrict traffic between the host device and the network device. It is determined whether the filtering parameters conflict with an initial filtering configuration. The filtering parameters may be applied to traffic through the network device.


