Network Switch Traffic Distribution for Suspicious Packet Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identifying suspicious network traffic is challenging and expensive due to the inability of existing methods to determine the network location of origin and the complexity and cost of using load-balancers for network security.
Innovation Solution
Configuring a network switch to selectively distribute copied network traffic to analysis hosts in a stateful manner, encapsulating packets to preserve source-destination information, and using a false source identifier to determine potentially suspicious activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If load-balancers are used to identify suspicious network traffic, then network security detection capability is improved, but device cost and complexity increase
Solution Approach 1:
The patent creates a copy of network traffic packets and redirects them to analysis hosts for security inspection. The original traffic flow continues uninterrupted while a duplicate copy is sent to the load balancer and analysis hosts, allowing security detection without adding complexity to the main network path. This copying approach enables sophisticated security analysis using inexpensive hardware rather than requiring complex load-balancer infrastructure.
2Reliability
If load-balancers are used to identify suspicious network traffic, then network security detection capability is improved, but device cost increases
Solution Approach 1:
The patent replaces expensive load-balancer hardware with inexpensive analysis hosts that can be deployed as commodity servers. The system uses standard network switches and affordable computing resources to perform security analysis, eliminating the need for costly specialized load-balancing equipment while maintaining effective suspicious traffic detection capabilities.
3Measurement precision
If network traffic content analysis is performed to identify suspicious traffic, then detection accuracy is improved, but ability to identify network location of origin is lost
Solution Approach 1:
The patent segments packet information into distinct components: header data containing network location information (source IP, destination IP, ports) and payload data containing content information. The analysis hosts separately process these segments, extracting both the content for suspicious activity detection and the header information for network location identification. This segmentation allows simultaneous preservation of both detection accuracy and location tracking capability.
Data Source
AI summary
The disclosure includes a method that includes receiving network traffic having a first plurality of packets that each indicate a first packet source and a first packet destination; determining an analysis host destination for each of the first plurality of packets such that the packets are distributed among a plurality of analysis hosts with communications between a given source-destination pair being sent to the same analysis host; encapsulating the first plurality of packets to generate a second plurality of encapsulated packets having the first plurality of packets as a second packet payload; and sending the second plurality of encapsulated packets to respective analysis host destinations.


