Packet Tunneling for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large computing networks, deploying intrusion systems (IS) in-line with every network device to detect suspicious activity is expensive and complex, as it requires numerous IS installations to cover all edge ports, leading to incomplete network coverage.
Innovation Solution
Implementing network devices with logic to select and transparently tunnel data packets to a secondary network device, where an IS can perform security checks without being in-line with the original packet path, allowing fewer IS installations to monitor multiple ports across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If intrusion systems are deployed in-line with every network device to detect suspicious activity, then security coverage is improved, but deployment cost and system complexity increase significantly
Solution Approach 1:
The patent introduces a network device as an intermediary that includes both the intrusion system and tunneling functionality. This intermediary device selectively tunnels packets from multiple network devices to a centralized intrusion system, eliminating the need to deploy in-line IS at every network device while maintaining comprehensive security coverage.
Solution Approach 2:
The patent transitions from a distributed in-line deployment model (one-dimensional approach at each network device) to a centralized out-of-band deployment model (adding a new dimension of packet routing through tunneling). This allows the intrusion system to be positioned outside the original packet path while still intercepting and analyzing traffic from multiple sources.
2Reliability
If multiple intrusion systems are installed to cover all edge ports, then monitoring capability is improved, but maintenance complexity and cost increase
Solution Approach 1:
The patent merges multiple monitoring functions into a single centralized intrusion system. Instead of installing and maintaining separate IS instances at each network device, the solution consolidates all intrusion detection functionality into one system that receives tunneled packets from multiple sources, significantly reducing maintenance complexity.
Solution Approach 2:
The centralized intrusion system performs multiple monitoring functions for different network devices through a single deployment. The system analyzes packets from multiple edge ports and network devices universally, eliminating the need for device-specific IS installations and simplifying maintenance across the entire network.
3Reliability
If intrusion systems are placed in-line at initial client and server attach points, then suspicious activity detection is improved, but implementation cost increases
Solution Approach 1:
The network device acts as an intermediary that enables the centralized intrusion system to access packets from multiple network devices without requiring in-line placement. This intermediary functionality is already present in standard network devices, eliminating the need for additional expensive in-line IS hardware at each attach point.
Solution Approach 2:
The tunneling mechanism creates copies of packets from multiple network devices and routes them to the centralized intrusion system. This copying approach allows the single IS to analyze traffic from multiple sources simultaneously, replacing the need for multiple expensive in-line IS installations while maintaining comprehensive detection capability.
Data Source
AI summary
Network devices, systems, and methods are provided for packet processing. One network device includes a network chip having a number of network ports for the device. The network chip includes logic to select original data packets, based on a set of criteria, received from or destined to a particular port on the device and to tunnel the selected data packets to a second network device having a different destination address to that of the selected data packets.


