Intrusion Prevention Sensor Session Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion prevention systems (IPS) can cause network outages when detecting failures, as they are designed to respond reactively and sit inline with traffic flows, potentially disrupting ongoing sessions.

Innovation Solution

Implementing a network infrastructure with primary and back-up sensors configured to share connection and session information via a communication link, ensuring seamless session maintenance during network failures by transferring data before reconverging to a new path, utilizing spanning tree protocol awareness to activate back-up sensors and maintain session integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the IPS sits inline with traffic flows and responds reactively to suspicious activity, then the system can block malicious traffic in real-time, but the system may cause network outages when detecting network failures

Engineering Contradiction:
Improvenetwork availabilityVSAvoidnetwork outages
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a proactive failover mechanism where the backup sensor is pre-configured and synchronized with the primary sensor before any failure occurs. Connection and session information is continuously replicated to the backup sensor, enabling immediate takeover without network interruption when the primary sensor fails, thus preventing network outages while maintaining real-time threat blocking capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a communication link as an intermediary between the primary and backup sensors. This intermediary channel enables seamless transfer of connection and session information, allowing the backup sensor to assume the role of the primary sensor without disrupting network traffic flows, thereby eliminating network outages while preserving intrusion prevention functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the IPS terminates connections upon detecting suspicious activity, then malicious traffic can be blocked, but ongoing user sessions may be interrupted

Engineering Contradiction:
Improvemalicious traffic blockingVSAvoiduser session continuity
Core Design Contradiction:
Object-affected harmful factorsVSDuration of action of stationary object

Solution Approach 1:

The patent creates a replicated copy of connection and session information from the primary sensor to the backup sensor. This copying mechanism ensures that when failover occurs, the backup sensor already possesses complete session state information, allowing it to maintain ongoing user sessions without interruption while continuing to block malicious traffic through the same sensor instances

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7836360B2System and method for intrusion prevention high availability fail over
Publication Date: 2010.11.16 KYNDRYL INC
  • US7836360B2 patent drawing
  • US7836360B2 patent drawing
  • US7836360B2 patent drawing

AI summary

A system and method for intrusion prevention high availability fail over. The system includes a network infrastructure which comprises a first sensor and at least one back-up sensor. The first sensor and the at least one back-up sensor are in line with a network path. The first sensor and the at least one back-up sensor are configured to share connection and session information via a communication link.