Packet Transfer Device Address Replacement for Shared Harmful Packet Removal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for preventing obstruction access in networks, such as harmful packet removal, require either expensive customer-specific solutions or shared apparatuses that burden service providers with additional costs and performance degradation due to software processing or hardware installation, and involve complex routing changes.
Innovation Solution
A packet transfer apparatus with multiple network interfaces, storage for attack target patterns, and Ethernet address replacement capabilities, allowing packets to be routed to a harmful packet removal apparatus without altering routing information, thereby eliminating the need for tunnels and reducing operational costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a harmful packet removal apparatus is inserted into each customer's connection line, then harmful packets can be effectively removed, but the service becomes expensive
Solution Approach 1:
The harmful packet removal apparatus is designed to serve multiple customers simultaneously through a shared infrastructure. The apparatus can identify and filter harmful packets for different customer networks based on destination address patterns, eliminating the need for separate dedicated apparatuses for each customer while maintaining effective harmful packet removal.
2Reliability
If routing information is rewritten to guide packets to the harmful packet removal apparatus, then harmful packets can be filtered, but the network complexity and operational costs increase
Solution Approach 1:
A packet transfer apparatus is introduced as an intermediary between the customer network and the harmful packet removal apparatus. This intermediary handles the packet forwarding and address translation functions, allowing the harmful packet removal apparatus to operate independently without requiring complex routing changes in the customer network. The packet transfer apparatus translates destination addresses and forwards packets appropriately.
3Ease of operation
If a tunnel is established from the harmful packet removal apparatus to the customer network, then packets can be returned to the intended destination, but additional hardware and software processing are required
Solution Approach 1:
The packet transfer apparatus serves as an intermediary that handles the packet return function without requiring tunnel establishment. Instead of creating a tunnel from the harmful packet removal apparatus to the customer network, the packet transfer apparatus simply forwards packets based on translated destination addresses, eliminating the need for complex tunnel termination hardware and software processing.
4Ease of manufacture
If software processing is used to terminate the tunnel, then no additional hardware is needed, but router performance deteriorates
Solution Approach 1:
The packet transfer apparatus acts as a dedicated intermediary device that handles packet forwarding and address translation functions. By offloading these functions to a specialized apparatus rather than using software processing on general-purpose routers, the solution avoids performance deterioration while not requiring additional expensive hardware at customer premises.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A packet transfer apparatus is provided with: storage means configured to store a predetermined search pattern and an address identifying a predetermined apparatus; determination means configured to determine whether predetermined data in a packet received from a network interface matches the search pattern; determination means configured to determine a network interface for outputting the packet using the determination result; replacement means configured to replace an address identifying a destination apparatus of the packet with an address identifying the predetermined apparatus when outputting the packet from a network interface connected to the predetermined apparatus; and packet sending means configured to send the packet to the determined network interface.