Network Inspection Device Capability Advertisement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems suffer from underutilization of security portfolios and redundant inspections due to devices inspecting traffic on a first encounter basis, leading to inefficient use of inspection capabilities and duplicate efforts among devices.

Innovation Solution

Security/inspection devices advertise their capabilities and adjust their configurations to optimize the utilization of network security portfolios by deferring inspections to more capable devices, using techniques such as inspection capabilities advertisement (ICA) and secure communication channels to ensure that only necessary inspections are performed, thereby reducing redundant efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices inspect traffic on a first encounter basis, then traffic security inspection is performed, but security portfolio utilization is underutilized and redundant inspections occur

Engineering Contradiction:
Improvesecurity inspectionVSAvoidsecurity portfolio utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Devices advertise their inspection capabilities in advance before traffic arrives. This preliminary capability advertisement allows subsequent traffic inspection decisions to be made optimally by knowing which devices can perform which inspections, enabling the system to route traffic to the most appropriate device rather than relying on first-encounter inspection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where inspection devices advertise their capabilities to neighboring devices. This capability information flows back through the network, allowing devices to make informed decisions about traffic routing and inspection delegation, thereby optimizing security portfolio utilization and eliminating redundant inspections.

Inventive Principle:
Principle #23Feedback

2Reliability

If multiple devices perform inspection, then comprehensive security coverage is achieved, but duplicate/redundant inspection occurs

Engineering Contradiction:
Improvesecurity coverageVSAvoidredundant inspection effort
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Multiple inspection capabilities are merged into a coordinated system where devices share their inspection results. When a device performs an inspection, it can mark packets or communicate results to subsequent devices, allowing the inspection function to be merged across multiple devices rather than having each device independently perform all inspections.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces intermediary mechanisms such as packet marking and capability advertisement protocols that mediate between inspection devices. These intermediaries enable devices to understand which inspections have already been performed and prevent redundant work, while still maintaining comprehensive security coverage through coordinated multi-device inspection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If inspection capabilities are advertised and configurations tuned, then security portfolio utilization is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity portfolio utilizationVSAvoidinspection configuration management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Devices perform self-service by automatically advertising their own capabilities and receiving capability information from neighboring devices. The inspection configuration is tuned automatically based on this exchanged information, eliminating the need for manual configuration management and reducing operational complexity while improving security portfolio utilization.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The capability advertisement and configuration tuning mechanism provides universal functionality across different inspection devices. A single standardized protocol enables devices to automatically adapt their inspection behavior based on their capabilities and the capabilities of neighboring devices, reducing complexity compared to device-specific configuration management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12074847B2Advertising device inspection capabilities to enhance network traffic inspections
Publication Date: 2024.08.27 CISCO TECHNOLOGY INC
  • US12074847B2 patent drawing
  • US12074847B2 patent drawing
  • US12074847B2 patent drawing

AI summary

Techniques for advertising device inspection capabilities to enhance network traffic inspections are described herein. The techniques may include determining, by a first inspection device of a network, that a second inspection device is disposed within the network. The first inspection device may also receive, from the second inspection device, an indication that the second inspection device is capable of performing a first type of inspection. The techniques may also include receiving, at the first inspection device, a packet that is to be sent through the network along a path that includes the second inspection device. Based at least in part on the path including the second inspection device, the first inspection device may refrain from performing the first type of inspection on the packet at the first inspection device such that the second inspection device can perform the first type of inspection on the packet.