Network Blockade Policy for Security Alert Buffer Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security Alerting Systems face ambiguity in identifying the cause of 'heartbeat' alerts, where network failures can mimic adversarial activity, allowing attackers to hide their actions by blocking or delaying buffer transmissions, making it difficult to distinguish between benign and adversarial network issues.
Innovation Solution
Implementing a network blockage policy that remotely blocks a host's network connection if it fails to transmit alert buffers within a predefined time interval, using a message-locking channel that ensures integrity, stealthiness, and persistence of alert messages, and employing forward-secure logging to maintain cryptographic protections and buffer retransmissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If heartbeat alerts are monitored to detect transmission failures, then system reliability is improved, but the ability to distinguish between benign and adversarial causes deteriorates
Solution Approach 1:
The system implements feedback mechanisms where the collection server monitors heartbeat alerts and sends notifications back to the host. When a heartbeat alert is detected, the server notifies the host to resend the buffer, creating a feedback loop that helps distinguish between temporary network failures and adversarial blocking through observed responses.
Solution Approach 2:
The patent introduces an intermediary notification mechanism between the collection server and host. The server sends notifications to the host about missing heartbeats, which then triggers resending behavior. This intermediary communication layer enables the system to differentiate between benign delays (where the host may have been notified and is resending) and adversarial blocking (where the host compounds the blockage).
2Object-affected harmful factors
If network blockage policy is implemented to prevent attacker actions, then security is improved, but network availability for legitimate traffic deteriorates
Solution Approach 1:
The network blockage policy applies local quality by selectively blocking network connections based on specific conditions (failure to respond to heartbeat alerts after notification). Not all network traffic is blocked uniformly, but rather the blocking is applied locally to specific host connections that exhibit adversarial behavior patterns, while maintaining normal network availability for legitimate traffic.
Solution Approach 2:
The system implements dynamic network blockage where the blocking state changes based on observed behavior. The collection server monitors whether hosts respond to heartbeat alert notifications by resending buffers. If hosts continue to block after notification, the server dynamically updates the network blockage state. This dynamic approach allows the system to adapt network availability based on real-time security observations.
Data Source
AI summary
A security alerting system is provided with a network blockage policy based on alert transmission activity. Alert messages from a Security Alerting System executing on a host indicating a potential compromise of a protected resource are processed by determining if a number of buffer contents received from the host within a predefined time interval satisfies a predefined criteria, the buffer content comprising one or more of the alert messages from the Security Alerting System; and blocking a network connection of the host if the number of buffer contents received from the host within the predefined time interval does not satisfy the predefined criteria. The blocked network connection of the host can optionally be restored when a valid buffer content is received from the host. The predefined criteria is based on the alerting activity of the host.


