Network Switch Traffic Distribution for Suspicious Packet Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying suspicious network traffic is challenging and expensive due to the inability of existing methods to determine the network location of origin and the complexity and cost of using load-balancers for network security.

Innovation Solution

Configuring a network switch to selectively distribute copied network traffic to analysis hosts in a stateful manner, encapsulating packets to preserve source-destination information, and using a false source identifier to determine potentially suspicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If load-balancers are used to identify suspicious network traffic, then network security detection capability is improved, but device cost and complexity increase

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a copy of network traffic packets and redirects them to analysis hosts for security inspection. The original traffic flow continues uninterrupted while a duplicate copy is sent to the load balancer and analysis hosts, allowing security detection without adding complexity to the main network path. This copying approach enables sophisticated security analysis using inexpensive hardware rather than requiring complex load-balancer infrastructure.

Inventive Principle:
Principle #26Copying

2Reliability

If load-balancers are used to identify suspicious network traffic, then network security detection capability is improved, but device cost increases

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces expensive load-balancer hardware with inexpensive analysis hosts that can be deployed as commodity servers. The system uses standard network switches and affordable computing resources to perform security analysis, eliminating the need for costly specialized load-balancing equipment while maintaining effective suspicious traffic detection capabilities.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Measurement precision

If network traffic content analysis is performed to identify suspicious traffic, then detection accuracy is improved, but ability to identify network location of origin is lost

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork location information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments packet information into distinct components: header data containing network location information (source IP, destination IP, ports) and payload data containing content information. The analysis hosts separately process these segments, extracting both the content for suspicious activity detection and the header information for network location identification. This segmentation allows simultaneous preservation of both detection accuracy and location tracking capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20210006580A1System and method for identifying suspicious network traffic
Publication Date: 2021.01.07 AMAZON TECH INC
  • US20210006580A1 patent drawing
  • US20210006580A1 patent drawing
  • US20210006580A1 patent drawing

AI summary

The disclosure includes a method that includes receiving network traffic having a first plurality of packets that each indicate a first packet source and a first packet destination; determining an analysis host destination for each of the first plurality of packets such that the packets are distributed among a plurality of analysis hosts with communications between a given source-destination pair being sent to the same analysis host; encapsulating the first plurality of packets to generate a second plurality of encapsulated packets having the first plurality of packets as a second packet payload; and sending the second plurality of encapsulated packets to respective analysis host destinations.