Network Gateway Filtering Penetration Testing Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Penetration testing in remotely managed networks can trigger false alarms at the remote network management platform, leading to unintended shutdowns of critical services due to misidentification as potential attacks, and existing solutions lack dynamic and secure management of network traffic and data encryption.
Innovation Solution
A gateway device within the managed network is configured with a list of trusted network addresses to filter and encrypt traffic, dynamically updated by security devices to block compromised devices and encrypt sensitive data, ensuring secure communication and preventing false alarms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If penetration testing scans are performed against network addresses assigned to computational instances, then security assessment is improved, but false alarms trigger shutdowns of critical services
Solution Approach 1:
The gateway device acts as an intermediary between the managed network and the computational instance. It inspects network traffic and selectively forwards only legitimate penetration testing traffic while blocking malicious traffic, preventing false alarms from triggering shutdowns while still enabling security assessments
Solution Approach 2:
The system uses feedback from security devices (firewalls, intrusion detection systems) to dynamically update the blocklist of compromised devices. This feedback mechanism allows the gateway to learn from security events and adjust its filtering behavior, preventing false alarms while maintaining security assessment capabilities
2Reliability
If the remote network management platform shuts down access to computational instances in response to perceived attacks, then security is improved, but service availability deteriorates
Solution Approach 1:
The gateway device serves as a mediator that intercepts and filters network traffic before it reaches the computational instance. By identifying legitimate penetration testing traffic and allowing it through while blocking actual attacks, the gateway enables the system to maintain service availability while still responding to security threats
Solution Approach 2:
The gateway applies different filtering policies to different types of traffic based on their source addresses. Legitimate penetration testing traffic from known security devices is allowed, while traffic from compromised devices is blocked. This localized differentiation enables the system to maintain service availability for authorized operations while responding to actual security breaches
3Reliability
If network traffic is encrypted end-to-end, then data security is improved, but performance deteriorates due to encryption/decryption overhead
Solution Approach 1:
The gateway applies encryption selectively only to traffic that requires it, rather than encrypting all traffic end-to-end. It identifies traffic from trusted sources that can be decrypted locally and applies encryption only to traffic from untrusted sources, thereby reducing encryption/decryption overhead while maintaining data security where needed
Solution Approach 2:
The gateway performs preliminary inspection of network traffic before encryption or forwarding decisions are made. By analyzing source addresses and traffic patterns in advance, it can pre-determine which traffic needs encryption and which can be handled locally, reducing the need for extensive encryption operations and improving overall performance
Data Source
AI summary
A gateway device disposed within a managed network may be communicatively coupled to a computational instance of a remote network management platform. The gateway device may also be configured with a list of network addresses assigned to the managed network, and configured to: receive network traffic from computing devices on the managed network, compare source addresses of the network traffic to the network addresses in the list, discard a first unit of the network traffic that has source addresses that are specified in the list, and for a second unit of the network traffic with source addresses that are not specified by the list, (i) encrypt, as a whole, payloads of each packet of the second unit of the network traffic, and (ii) transmit the encrypted packets from the gateway device to the computational instance. Network addresses in the list may be provided by a gateway controller device.


