Multicast Traffic Encapsulation for Industrial Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional Switch Port Analyzer (SPAN) based security mechanisms in industrial networks lead to exponential bandwidth overhead, disrupting production processes and compromising security monitoring due to high bandwidth consumption, especially in large ring topologies.

Innovation Solution

Implementing a multicast encapsulation mechanism to convey traffic duplicates to network sensors for analysis, where intermediary devices forward multicast traffic via uplink ports, preventing bandwidth explosion and minimizing overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SPAN-based security mechanisms are used to monitor network traffic, then security analysis capability is improved, but bandwidth consumption increases exponentially

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent introduces a multicast encapsulation mechanism that acts as an intermediary between the SPAN traffic source and the security analyzer. Instead of directly copying and forwarding traffic through traditional SPAN ports, the system encapsulates traffic in multicast frames with reserved destination MAC addresses (01:00:5E:00:00:01 or 01:00:5E:00:00:02). This intermediary approach allows traffic to be efficiently distributed to multiple analyzers simultaneously without exponential bandwidth consumption, as the encapsulated frames are forwarded only to devices that have joined the corresponding multicast groups.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the addressing parameter of traffic forwarding from traditional unicast or broadcast SPAN port addresses to reserved multicast MAC addresses. By assigning specific reserved multicast addresses (01:00:5E:00:00:01 for ingress, 01:00:5E:00:00:02 for egress) to security analysis functions, the system enables efficient multicast-based traffic distribution. This parameter change transforms the forwarding behavior from copying traffic to every SPAN port to intelligent distribution only to devices that have explicitly joined the multicast group, thereby reducing bandwidth overhead.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If traditional SPAN protocol is used for traffic analysis, then security posture detection is enabled, but production process disruption occurs due to high bandwidth overhead

Engineering Contradiction:
Improvesecurity posture visibilityVSAvoidproduction process continuity
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The multicast encapsulation mechanism serves as an intermediary that separates the traffic analysis function from the production traffic flow. By encapsulating production traffic in multicast frames with reserved destination addresses, the system enables security analysis without requiring traditional SPAN port copies that consume excessive bandwidth. The intermediary multicast forwarding mechanism ensures that only the necessary traffic reaches security analyzers, preventing bandwidth exhaustion that would disrupt production processes while maintaining full visibility into security posture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If SPAN-based security mechanisms are deployed in large ring topologies, then network security monitoring is achieved, but bandwidth overhead increases exponentially with ring size

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidbandwidth overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces multicast encapsulation as an intermediary mechanism that fundamentally changes how traffic is distributed in ring topologies. Instead of traditional SPAN copying that causes exponential bandwidth growth as traffic traverses each switch in the ring, the system encapsulates traffic in multicast frames with reserved destination MAC addresses. These frames are efficiently distributed only to devices that have joined the multicast group, preventing the exponential bandwidth overhead that occurs in large ring topologies with traditional SPAN.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The reserved multicast addresses serve multiple functions simultaneously: they identify security analysis traffic, enable efficient multicast group distribution, and provide a universal addressing scheme that works across networks of any size. This multi-functional addressing mechanism eliminates the need for separate SPAN port configurations at each switch in the ring, thereby preventing bandwidth overhead from increasing exponentially with network scale.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11916972B2Traffic capture mechanisms for industrial network security
Publication Date: 2024.02.27 CISCO TECHNOLOGY INC
  • US11916972B2 patent drawing
  • US11916972B2 patent drawing
  • US11916972B2 patent drawing

AI summary

According to various embodiments, a networking device in a network receives traffic from the network. The networking device duplicates the traffic into a duplicate traffic copy. The networking device encapsulates the duplicate traffic copy into a multicast frame. The networking device sends, via a multicast address, the multicast frame to a network sensor in the network for analysis, wherein the multicast address is reserved in the network for traffic analysis.