Marked Packet Forwarding for Centralized Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network intrusion systems (IS) are expensive and complex to implement and maintain, especially in large networks, as they often require dedicated in-line devices or dispersed integral configurations, which may not effectively detect suspicious activity if not properly positioned in the network traffic path.

Innovation Solution

A centralized network intrusion system (IS) is implemented, where network devices securely tunnel data packets to a remote checking functionality, marking them with a handle to track their originating device, allowing for efficient detection and processing without the need for dedicated resources at each network device, thereby reducing costs and complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a centralized intrusion system is implemented, then implementation cost and device complexity are reduced, but the ability to detect suspicious activity in real-time may be compromised due to packet tunneling overhead

Engineering Contradiction:
ImproveIS configuration complexityVSAvoidsuspicious activity detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

A remote network device acts as an intermediary between originating network devices and the centralized checking functionality. This intermediary receives tunneled packets, removes encapsulation, marks packets with handles, and forwards them to the checking functionality, thereby simplifying the overall system architecture while maintaining detection capability through centralized analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The intrusion detection function is segmented into distinct components: packet tunneling at originating devices, intermediate processing at remote network devices (decapsulation, marking), and centralized analysis at the checking functionality. This segmentation allows each component to be optimized independently while working together to solve the contradiction between centralization and detection effectiveness

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If packets are tunneled to a remote device for checking, then centralized security management is achieved, but packet processing time increases due to additional tunneling and marking steps

Engineering Contradiction:
Improvecentralized security management capabilityVSAvoidpacket processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The remote network device performs preliminary actions by pre-establishing handle mappings and preparing packet marking templates before actual intrusion detection is needed. This allows packets to be quickly marked and forwarded during operation without time-consuming setup, reducing processing time while maintaining centralized management

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes packet parameters by adding handles and VLAN tags during tunneling and marking processes. These parameter changes enable centralized tracking and analysis while the changes are designed to be minimal and efficient, reducing the time overhead associated with packet modification

Inventive Principle:
Principle #35Parameter changes

3Area of stationary object

If all network devices tunnel packets to a centralized checking functionality, then comprehensive network coverage is achieved, but network bandwidth is consumed by tunneling overhead

Engineering Contradiction:
Improvenetwork coverage areaVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
Area of stationary objectVSLoss of energy

Solution Approach 1:

The handle marking mechanism serves multiple functions simultaneously: it identifies the originating network device, tracks packet flow through the tunnel, enables centralized analysis, and facilitates packet return routing. This multi-functionality reduces the need for separate mechanisms, thereby reducing overall bandwidth consumption while achieving comprehensive network coverage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8611351B2Marked packet forwarding
Publication Date: 2013.12.17 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8611351B2 patent drawing
  • US8611351B2 patent drawing
  • US8611351B2 patent drawing

AI summary

A network, network devices, and methods are described for marked packet forwarding. A network device includes a network chip having a number of network ports for receiving and transmitting packets. The network chip includes logic to decapsulate a packet received from a tunnel, mark the packet with a handle associated with an originating network device of the packet using information from an encapsulation header, and forward the marked packet to a checking functionality having a destination address different from an original destination address of the packet.