Delegating Host Security Filtering to Network Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures, such as firewalls and RADIUS servers, are inadequate in providing real-time, host device-specific threat filtering, as they often rely on generalized threat detection rules and resource-intensive software applications, which can be overwhelmed during attacks like denial-of-service (DOS) scenarios.

Innovation Solution

A method where host devices dynamically generate and enforce security-based filtering parameters with network devices, such as switches, to restrict traffic and isolate threats, leveraging access control lists (ACLs) and offloading filtering tasks from host devices to network switches for improved performance and specificity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If filtering is performed at the host device using a personal firewall, then host-specific threat filtering is achieved, but resource consumption increases significantly

Engineering Contradiction:
Improvehost-specific filtering accuracyVSAvoidhost device resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts the filtering function from the host device and relocates it to the network switch. The host device generates filtering parameters locally, but the actual traffic filtering is performed by the network switch, thereby reducing host resource consumption while maintaining host-specific filtering capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network switch acts as an intermediary between the host device and the network traffic. It receives filtering parameters from the host device and enforces them by analyzing and filtering traffic, thereby offloading the resource-intensive filtering task from the host device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If generalized threat detection rules are used to handle multiple sampling streams, then network-wide security coverage is improved, but host device-specific protection is reduced

Engineering Contradiction:
Improvenetwork-wide security coverageVSAvoidhost device-specific filtering accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent segments the security function into two parts: network-wide security policies are enforced by the network switch, while host-specific filtering parameters are generated by the host device. This segmentation allows both network-wide coverage and host-specific protection to coexist effectively.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The host device generates filtering parameters locally based on its specific security needs and threat detection, while the network switch enforces these parameters. This local quality approach ensures that each host receives customized security filtering tailored to its specific requirements while still benefiting from network-wide security coverage.

Inventive Principle:
Principle #3Local quality

3Speed

If real-time filtering parameters are applied dynamically, then response time to threats is improved, but system complexity increases

Engineering Contradiction:
Improvereal-time threat response speedVSAvoidfiltering system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The host device autonomously generates and updates filtering parameters in real-time based on its security needs and detected threats. This self-service capability allows dynamic response to threats without requiring complex centralized control, thereby improving response speed while managing system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8904514B2Implementing a host security service by delegating enforcement to a network device
Publication Date: 2014.12.02 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8904514B2 patent drawing
  • US8904514B2 patent drawing
  • US8904514B2 patent drawing

AI summary

A method for applying a host security service to a network is described herein. The network may include a host device and a network device. The network device may receive a request for security-based filtering. The request includes filtering parameters that restrict traffic between the host device and the network device. It is determined whether the filtering parameters conflict with an initial filtering configuration. The filtering parameters may be applied to traffic through the network device.