Packet Tunneling for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large computing networks, deploying intrusion systems (IS) in-line with every network device to detect suspicious activity is expensive and complex, as it requires numerous IS installations to cover all edge ports, leading to incomplete network coverage.

Innovation Solution

Implementing network devices with logic to select and transparently tunnel data packets to a secondary network device, where an IS can perform security checks without being in-line with the original packet path, allowing fewer IS installations to monitor multiple ports across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusion systems are deployed in-line with every network device to detect suspicious activity, then security coverage is improved, but deployment cost and system complexity increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network device as an intermediary that includes both the intrusion system and tunneling functionality. This intermediary device selectively tunnels packets from multiple network devices to a centralized intrusion system, eliminating the need to deploy in-line IS at every network device while maintaining comprehensive security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from a distributed in-line deployment model (one-dimensional approach at each network device) to a centralized out-of-band deployment model (adding a new dimension of packet routing through tunneling). This allows the intrusion system to be positioned outside the original packet path while still intercepting and analyzing traffic from multiple sources.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multiple intrusion systems are installed to cover all edge ports, then monitoring capability is improved, but maintenance complexity and cost increase

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidmaintenance complexity
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent merges multiple monitoring functions into a single centralized intrusion system. Instead of installing and maintaining separate IS instances at each network device, the solution consolidates all intrusion detection functionality into one system that receives tunneled packets from multiple sources, significantly reducing maintenance complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized intrusion system performs multiple monitoring functions for different network devices through a single deployment. The system analyzes packets from multiple edge ports and network devices universally, eliminating the need for device-specific IS installations and simplifying maintenance across the entire network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If intrusion systems are placed in-line at initial client and server attach points, then suspicious activity detection is improved, but implementation cost increases

Engineering Contradiction:
Improvesuspicious activity detectionVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The network device acts as an intermediary that enables the centralized intrusion system to access packets from multiple network devices without requiring in-line placement. This intermediary functionality is already present in standard network devices, eliminating the need for additional expensive in-line IS hardware at each attach point.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The tunneling mechanism creates copies of packets from multiple network devices and routes them to the centralized intrusion system. This copying approach allows the single IS to analyze traffic from multiple sources simultaneously, replacing the need for multiple expensive in-line IS installations while maintaining comprehensive detection capability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8045550B2Packet tunneling
Publication Date: 2011.10.25 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8045550B2 patent drawing
  • US8045550B2 patent drawing
  • US8045550B2 patent drawing

AI summary

Network devices, systems, and methods are provided for packet processing. One network device includes a network chip having a number of network ports for the device. The network chip includes logic to select original data packets, based on a set of criteria, received from or destined to a particular port on the device and to tunnel the selected data packets to a second network device having a different destination address to that of the selected data packets.