Marked Packet Forwarding for Centralized Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network intrusion systems (IS) are expensive and complex to implement and maintain, especially in large networks, as they often require dedicated in-line devices or dispersed integral configurations, which may not effectively detect suspicious activity if not properly positioned in the network traffic path.
Innovation Solution
A centralized network intrusion system (IS) is implemented, where network devices securely tunnel data packets to a remote checking functionality, marking them with a handle to track their originating device, allowing for efficient detection and processing without the need for dedicated resources at each network device, thereby reducing costs and complexity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized intrusion system is implemented, then implementation cost and device complexity are reduced, but the ability to detect suspicious activity in real-time may be compromised due to packet tunneling overhead
Solution Approach 1:
A remote network device acts as an intermediary between originating network devices and the centralized checking functionality. This intermediary receives tunneled packets, removes encapsulation, marks packets with handles, and forwards them to the checking functionality, thereby simplifying the overall system architecture while maintaining detection capability through centralized analysis
Solution Approach 2:
The intrusion detection function is segmented into distinct components: packet tunneling at originating devices, intermediate processing at remote network devices (decapsulation, marking), and centralized analysis at the checking functionality. This segmentation allows each component to be optimized independently while working together to solve the contradiction between centralization and detection effectiveness
2Adaptability or versatility
If packets are tunneled to a remote device for checking, then centralized security management is achieved, but packet processing time increases due to additional tunneling and marking steps
Solution Approach 1:
The remote network device performs preliminary actions by pre-establishing handle mappings and preparing packet marking templates before actual intrusion detection is needed. This allows packets to be quickly marked and forwarded during operation without time-consuming setup, reducing processing time while maintaining centralized management
Solution Approach 2:
The system changes packet parameters by adding handles and VLAN tags during tunneling and marking processes. These parameter changes enable centralized tracking and analysis while the changes are designed to be minimal and efficient, reducing the time overhead associated with packet modification
3Area of stationary object
If all network devices tunnel packets to a centralized checking functionality, then comprehensive network coverage is achieved, but network bandwidth is consumed by tunneling overhead
Solution Approach 1:
The handle marking mechanism serves multiple functions simultaneously: it identifies the originating network device, tracks packet flow through the tunnel, enables centralized analysis, and facilitates packet return routing. This multi-functionality reduces the need for separate mechanisms, thereby reducing overall bandwidth consumption while achieving comprehensive network coverage
Data Source
AI summary
A network, network devices, and methods are described for marked packet forwarding. A network device includes a network chip having a number of network ports for receiving and transmitting packets. The network chip includes logic to decapsulate a packet received from a tunnel, mark the packet with a handle associated with an originating network device of the packet using information from an encapsulation header, and forward the marked packet to a checking functionality having a destination address different from an original destination address of the packet.


