Network Traffic Monitoring via Port Hashing for Edge Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems, such as integral intrusion prevention and detection systems (IPS/IDS), are expensive and complex to maintain, especially in large networks, and often fail to selectively detect suspicious traffic at edge devices or monitor traffic in-line with network paths due to their core-focused implementation and non-integrated appliance monitoring.
Innovation Solution
Implementing logic and executable instructions on network devices to selectively monitor traffic based on source IP address, destination IP address, and VLAN membership, hashing destination TCP/UDP port numbers into a bit field to detect port scanning, and initiating remedial actions like rate limiting or dropping traffic when suspicious activity is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If integral IPS/IDS is deployed at each network device location, then network security detection capability is improved, but system cost and complexity increase significantly
Solution Approach 1:
The patent segments the intrusion detection function from the network device hardware and implements it as a separate software module that can be selectively deployed. Instead of requiring integral IPS/IDS at every device, the system divides the network into segments and places detection capabilities only where needed based on security policies, thereby reducing overall system complexity while maintaining detection capability.
Solution Approach 2:
The patent creates a universal intrusion detection system that can function across multiple network devices through a centralized management architecture. A single IPS/IDS software implementation can monitor multiple network segments and devices, eliminating the need for separate integral IPS/IDS at each location and reducing both cost and complexity.
2Device complexity
If integral IPS/IDS is placed only in core network, then cost is reduced, but ability to detect suspicious traffic at edge devices is compromised
Solution Approach 1:
The patent introduces network appliances as intermediary devices that bridge the gap between core network IPS/IDS and edge devices. These appliances act as local agents that can selectively monitor traffic at edge locations and relay information to the central IPS/IDS system, enabling distributed detection capability without requiring full integral IPS/IDS at every device.
Solution Approach 2:
The patent adds a new dimensional layer to the detection architecture by introducing software-based IPS/IDS that operates alongside traditional hardware-based systems. This software layer can be selectively enabled at different network levels (core, distribution, access), providing flexible detection coverage without the full cost of deploying integral IPS/IDS throughout the entire network.
3Adaptability or versatility
If network appliances are used to monitor traffic, then selective monitoring capability is improved, but ability to monitor traffic in-line with network path is lost
Solution Approach 1:
The patent merges the advantages of both approaches by combining the selective monitoring capability of network appliances with the in-line monitoring capability of integral IPS/IDS. The system allows administrators to configure hybrid architectures where some devices have integral IPS/IDS for in-line monitoring while others use network appliances for selective monitoring, thereby achieving both objectives simultaneously.
Data Source
AI summary
Systems, methods, and devices are described that monitor network traffic. One method includes monitoring a number of packets received by a network device based on a number of criteria to determine a flow of the packets. For each monitored packet for a particular source IP address/destination IP address pair, the method includes hashing a destination TCP/UDP port number into a range [0 . . . N]. The method further includes setting a bit in a bit field that has a width of N+1 bits based on the hashing.


