Network Chip Logic for Restoring Original Port Information
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network intrusion systems (IS) are costly and complex to maintain, especially in large networks, as they require dedicated resources dispersed throughout the network, and centralized IS configurations can lose ingress port information when tunneling packets, leading to incomplete detection of suspicious activity.
Innovation Solution
Implementing a network device with a network chip that includes logic to locate and restore original port information for tunneled packets, allowing them to bypass unnecessary forwarding protocols and re-establish their original path, thereby maintaining network security without the need for dedicated IS resources at each device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an intrusion system is deployed as a standalone in-line device to detect suspicious network traffic, then detection capability is improved, but implementation cost and maintenance complexity increase significantly
Solution Approach 1:
The patent combines the intrusion detection system with an existing network switch by integrating the IS into the switch's forwarding logic. This merging allows the switch itself to perform intrusion detection on packets it forwards, eliminating the need for a separate standalone IS device and reducing overall system complexity while maintaining detection capability.
Solution Approach 2:
The network switch is enhanced to perform multiple functions: standard packet forwarding and intrusion detection. By making the switch universal and capable of both forwarding packets and detecting intrusions within the same device, the patent reduces the number of separate components needed, thereby lowering implementation cost and maintenance complexity while preserving detection reliability.
2Reliability
If an intrusion system is integrated into individual network devices, then detection coverage is improved, but implementation cost and maintenance complexity remain high
Solution Approach 1:
The patent merges the intrusion detection function with the network switch's existing packet forwarding capability. By integrating IS into the switch rather than adding separate IS devices to each network device, the patent achieves broad detection coverage across the network while avoiding the high costs and complexity of deploying multiple standalone IS units.
Solution Approach 2:
The network switch is designed to universally handle both packet forwarding and intrusion detection tasks. This multi-functionality allows a single device type to provide comprehensive security coverage across the entire network, reducing the need for specialized IS hardware at each node and thereby lowering overall implementation costs.
3Device complexity
If packets are tunneled to a centralized intrusion system for checking, then resource dispersion is reduced, but original port information is lost
Solution Approach 1:
The patent applies preliminary action by modifying the packet tunneling process to preserve original port information before the packet is sent to the centralized intrusion system. The network switch stores the original ingress port information and restores it after the IS check, ensuring that no information is lost during the tunneling process while still achieving centralized resource consolidation.
Solution Approach 2:
The patent introduces an intermediary mechanism (the network switch) that acts as a mediator between the centralized intrusion system and the network packets. The switch preserves and restores original port information during the tunneling process, allowing centralized resource utilization while preventing information loss that would otherwise occur during packet diversion.
4Device complexity
If a centralized intrusion system is implemented without restoring original port information, then resource consolidation is improved, but detection accuracy deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-storing the original ingress port information in the network switch before packets are tunneled to the centralized intrusion system. This allows the IS to perform accurate detection based on original port context while resources remain consolidated centrally, resolving the contradiction between resource consolidation and detection accuracy.
Solution Approach 2:
The network switch serves as an intermediary that preserves critical port information during the packet tunneling process to the centralized IS. This intermediary function enables the centralized system to maintain high detection accuracy by having access to original port context, while still achieving resource consolidation benefits.
Data Source
AI summary
A network, network devices, and methods are described for locating original port information. A network device includes a network chip having a number of network ports for the device for receiving and transmitting packets. The network chip includes logic to locate original port information for a packet returned from a checking functionality.


