Network Sentries Divert Malicious Traffic via Isolated Slices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing networks are vulnerable to malicious attacks due to the processing of packets, which existing technologies have not effectively mitigated.
Innovation Solution
The method involves distributing sentries across the network to monitor traffic, analyze traffic status information, and create an isolated network slice with a deceptive resource to divert malicious traffic, while maintaining valid traffic flow.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network devices process packets to enable communication, then network functionality and connectivity are improved, but the network becomes vulnerable to malicious attacks
Solution Approach 1:
The patent introduces sentries as intermediary components deployed throughout the network that act as mediators between legitimate traffic and potential attacks. These sentries monitor traffic patterns and intercept malicious packets before they can compromise network resources, thereby enabling the network to maintain both functionality and security simultaneously
Solution Approach 2:
The network is segmented into multiple zones with sentries positioned at strategic points. This segmentation allows the network to process legitimate traffic normally while isolating and containing malicious attacks in specific segments, preventing attacks from compromising the entire network infrastructure
2Reliability
If traditional security measures are implemented to protect against attacks, then security is improved, but network traffic flow and communication efficiency deteriorate
Solution Approach 1:
The sentry system dynamically adjusts its monitoring and interception behavior based on real-time traffic analysis. During normal conditions, the system maintains minimal overhead to preserve traffic flow efficiency. When attacks are detected, the system dynamically increases its security measures, creating a responsive security mechanism that adapts to threats without permanently degrading network performance
Solution Approach 2:
The system implements continuous feedback loops where sentries monitor traffic patterns, analyze anomalies, and adjust their interception strategies in real-time. This feedback mechanism enables the system to distinguish between legitimate high-volume traffic and malicious attacks, maintaining productivity while enhancing security through intelligent, data-driven decisions
3Reliability
If network resources are allocated for attack mitigation, then security response capability is improved, but resource allocation efficiency deteriorates when no attack is present
Solution Approach 1:
Sentries are pre-deployed throughout the network infrastructure in a dormant or low-active state, positioned strategically to provide immediate response capability when attacks occur. This preliminary positioning ensures rapid security response when needed while minimizing resource consumption during normal operations, as the sentries only become fully active when detecting attack patterns
Solution Approach 2:
The system dynamically changes operational parameters of security resources based on threat levels. During normal conditions, sentries operate with minimal resource allocation. Upon detecting attacks, the system adjusts parameters such as monitoring intensity, interception aggressiveness, and resource allocation to match the threat level, thereby maintaining security response capability while optimizing resource efficiency
Data Source
AI summary
Systems and methods for mitigating network attacks include, responsive to detection of malicious traffic in a network, causing creation of an isolated network slice in the network where the isolated network slice is a set of connection resources that are allocated to a flow of traffic and that spans a plurality of network devices in the network; and causing rerouting of the malicious traffic from a source node of the malicious traffic to a deceptive network resource along the isolated network slice.


