Partitioned Intrusion Detection via Distributed Rule Application
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion prevention systems (IPS) face increased computational load and network latency due to the need for constant pattern matching with growing numbers of intrusion detection rules, which can lead to reduced efficacy in identifying security threats.
Innovation Solution
A distributed intrusion detection methodology where multiple network infrastructure devices apply portions of intrusion detection rules to packets, using overlay mechanisms like VXLAN, IPv6, or VLAN, to efficiently distribute and apply rules across the network, ensuring specified efficacy without overwhelming computational resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional intrusion detection rules are incorporated into the IPS inspection, then the ability to detect new intrusion threats is improved, but the computational load and network latency increase
Solution Approach 1:
The patent divides the intrusion detection rule set into multiple partitions and distributes these partitions across different network infrastructure devices. Each device applies only its assigned partition to packets, rather than all devices applying all rules. This segmentation reduces the computational load on each individual device while maintaining comprehensive threat detection coverage across the network.
2Measurement precision
If pattern matching determination is performed on all packets with all intrusion detection rules, then detection accuracy is improved, but computational resources are overwhelmed
Solution Approach 1:
The patent assigns different intrusion detection rule partitions to different network infrastructure devices based on their capabilities and roles. Each device applies the specific partition assigned to it, creating a localized division of labor. This ensures that computational resources are used efficiently while maintaining detection accuracy through comprehensive rule coverage across the distributed system.
Solution Approach 2:
The patent applies intrusion detection rules in a partial manner, where not all rules are applied to every packet by every device. Instead, each device applies only its assigned partition to relevant packets. This partial action approach reduces unnecessary computational overhead while ensuring that the complete rule set is applied across the network through the collective action of multiple devices.
3Ease of operation
If a single infrastructure device applies all intrusion detection rules, then ease of management is improved, but device complexity and processing bottleneck increase
Solution Approach 1:
The patent transitions from a single-device intrusion detection model to a multi-device distributed model, adding the dimension of spatial distribution across the network. This dimensional change allows the system to scale horizontally by adding more devices rather than increasing the capacity of a single device, thereby reducing processing bottlenecks while maintaining manageable complexity through automated partition distribution.
Data Source
AI summary
This disclosure describes methods to distribute intrusion detection in a network across multiple devices in the network, such as across routing/switching or other infrastructure devices. For example, as a packet is routed through a network infrastructure, an overlay mechanism may be utilized to indicate which of a total set of intrusion detection rules have been applied to the packet. Each infrastructure device may evaluate which rules have already been applied to the packet, using a result of the evaluation to determine where to route the packet in the network infrastructure for application of additional intrusion detection rules. Additionally, each infrastructure device may record a result of its application of the portion of intrusion detection rules directly into the packet.


