Network Traffic Monitoring via Port Hashing for Edge Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems, such as integral intrusion prevention and detection systems (IPS/IDS), are expensive and complex to maintain, especially in large networks, and often fail to selectively detect suspicious traffic at edge devices or monitor traffic in-line with network paths due to their core-focused implementation and non-integrated appliance monitoring.

Innovation Solution

Implementing logic and executable instructions on network devices to selectively monitor traffic based on source IP address, destination IP address, and VLAN membership, hashing destination TCP/UDP port numbers into a bit field to detect port scanning, and initiating remedial actions like rate limiting or dropping traffic when suspicious activity is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integral IPS/IDS is deployed at each network device location, then network security detection capability is improved, but system cost and complexity increase significantly

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the intrusion detection function from the network device hardware and implements it as a separate software module that can be selectively deployed. Instead of requiring integral IPS/IDS at every device, the system divides the network into segments and places detection capabilities only where needed based on security policies, thereby reducing overall system complexity while maintaining detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal intrusion detection system that can function across multiple network devices through a centralized management architecture. A single IPS/IDS software implementation can monitor multiple network segments and devices, eliminating the need for separate integral IPS/IDS at each location and reducing both cost and complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If integral IPS/IDS is placed only in core network, then cost is reduced, but ability to detect suspicious traffic at edge devices is compromised

Engineering Contradiction:
Improvesystem costVSAvoidsuspicious traffic detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces network appliances as intermediary devices that bridge the gap between core network IPS/IDS and edge devices. These appliances act as local agents that can selectively monitor traffic at edge locations and relay information to the central IPS/IDS system, enabling distributed detection capability without requiring full integral IPS/IDS at every device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimensional layer to the detection architecture by introducing software-based IPS/IDS that operates alongside traditional hardware-based systems. This software layer can be selectively enabled at different network levels (core, distribution, access), providing flexible detection coverage without the full cost of deploying integral IPS/IDS throughout the entire network.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If network appliances are used to monitor traffic, then selective monitoring capability is improved, but ability to monitor traffic in-line with network path is lost

Engineering Contradiction:
Improveselective monitoring capabilityVSAvoidin-line traffic monitoring capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges the advantages of both approaches by combining the selective monitoring capability of network appliances with the in-line monitoring capability of integral IPS/IDS. The system allows administrators to configure hybrid architectures where some devices have integral IPS/IDS for in-line monitoring while others use network appliances for selective monitoring, thereby achieving both objectives simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7924720B2Network traffic monitoring
Publication Date: 2011.04.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7924720B2 patent drawing
  • US7924720B2 patent drawing
  • US7924720B2 patent drawing

AI summary

Systems, methods, and devices are described that monitor network traffic. One method includes monitoring a number of packets received by a network device based on a number of criteria to determine a flow of the packets. For each monitored packet for a particular source IP address/destination IP address pair, the method includes hashing a destination TCP/UDP port number into a range [0 . . . N]. The method further includes setting a bit in a bit field that has a width of N+1 bits based on the hashing.