Network Sentries Divert Malicious Traffic via Isolated Slices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing networks are vulnerable to malicious attacks due to the processing of packets, which existing technologies have not effectively mitigated.

Innovation Solution

The method involves distributing sentries across the network to monitor traffic, analyze traffic status information, and create an isolated network slice with a deceptive resource to divert malicious traffic, while maintaining valid traffic flow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network devices process packets to enable communication, then network functionality and connectivity are improved, but the network becomes vulnerable to malicious attacks

Engineering Contradiction:
Improvenetwork functionalityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces sentries as intermediary components deployed throughout the network that act as mediators between legitimate traffic and potential attacks. These sentries monitor traffic patterns and intercept malicious packets before they can compromise network resources, thereby enabling the network to maintain both functionality and security simultaneously

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network is segmented into multiple zones with sentries positioned at strategic points. This segmentation allows the network to process legitimate traffic normally while isolating and containing malicious attacks in specific segments, preventing attacks from compromising the entire network infrastructure

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional security measures are implemented to protect against attacks, then security is improved, but network traffic flow and communication efficiency deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic flow efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The sentry system dynamically adjusts its monitoring and interception behavior based on real-time traffic analysis. During normal conditions, the system maintains minimal overhead to preserve traffic flow efficiency. When attacks are detected, the system dynamically increases its security measures, creating a responsive security mechanism that adapts to threats without permanently degrading network performance

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements continuous feedback loops where sentries monitor traffic patterns, analyze anomalies, and adjust their interception strategies in real-time. This feedback mechanism enables the system to distinguish between legitimate high-volume traffic and malicious attacks, maintaining productivity while enhancing security through intelligent, data-driven decisions

Inventive Principle:
Principle #23Feedback

3Reliability

If network resources are allocated for attack mitigation, then security response capability is improved, but resource allocation efficiency deteriorates when no attack is present

Engineering Contradiction:
Improvesecurity response capabilityVSAvoidresource allocation efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Sentries are pre-deployed throughout the network infrastructure in a dormant or low-active state, positioned strategically to provide immediate response capability when attacks occur. This preliminary positioning ensures rapid security response when needed while minimizing resource consumption during normal operations, as the sentries only become fully active when detecting attack patterns

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes operational parameters of security resources based on threat levels. During normal conditions, sentries operate with minimal resource allocation. Upon detecting attacks, the system adjusts parameters such as monitoring intensity, interception aggressiveness, and resource allocation to match the threat level, thereby maintaining security response capability while optimizing resource efficiency

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11770408B2Method and system of mitigating network attacks
Publication Date: 2023.09.26 CIENA CORP
  • US11770408B2 patent drawing
  • US11770408B2 patent drawing
  • US11770408B2 patent drawing

AI summary

Systems and methods for mitigating network attacks include, responsive to detection of malicious traffic in a network, causing creation of an isolated network slice in the network where the isolated network slice is a set of connection resources that are allocated to a flow of traffic and that spans a plurality of network devices in the network; and causing rerouting of the malicious traffic from a source node of the malicious traffic to a deceptive network resource along the isolated network slice.