Partitioned Intrusion Detection via Distributed Rule Application

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion prevention systems (IPS) face increased computational load and network latency due to the need for constant pattern matching with growing numbers of intrusion detection rules, which can lead to reduced efficacy in identifying security threats.

Innovation Solution

A distributed intrusion detection methodology where multiple network infrastructure devices apply portions of intrusion detection rules to packets, using overlay mechanisms like VXLAN, IPv6, or VLAN, to efficiently distribute and apply rules across the network, ensuring specified efficacy without overwhelming computational resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional intrusion detection rules are incorporated into the IPS inspection, then the ability to detect new intrusion threats is improved, but the computational load and network latency increase

Engineering Contradiction:
Improveintrusion detection effectivenessVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the intrusion detection rule set into multiple partitions and distributes these partitions across different network infrastructure devices. Each device applies only its assigned partition to packets, rather than all devices applying all rules. This segmentation reduces the computational load on each individual device while maintaining comprehensive threat detection coverage across the network.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If pattern matching determination is performed on all packets with all intrusion detection rules, then detection accuracy is improved, but computational resources are overwhelmed

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent assigns different intrusion detection rule partitions to different network infrastructure devices based on their capabilities and roles. Each device applies the specific partition assigned to it, creating a localized division of labor. This ensures that computational resources are used efficiently while maintaining detection accuracy through comprehensive rule coverage across the distributed system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies intrusion detection rules in a partial manner, where not all rules are applied to every packet by every device. Instead, each device applies only its assigned partition to relevant packets. This partial action approach reduces unnecessary computational overhead while ensuring that the complete rule set is applied across the network through the collective action of multiple devices.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If a single infrastructure device applies all intrusion detection rules, then ease of management is improved, but device complexity and processing bottleneck increase

Engineering Contradiction:
Improvesystem management simplicityVSAvoidinfrastructure device processing capacity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent transitions from a single-device intrusion detection model to a multi-device distributed model, adding the dimension of spatial distribution across the network. This dimensional change allows the system to scale horizontally by adding more devices rather than increasing the capacity of a single device, thereby reducing processing bottlenecks while maintaining manageable complexity through automated partition distribution.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11646995B2Partitioned intrusion detection
Publication Date: 2023.05.09 CISCO TECHNOLOGY INC
  • US11646995B2 patent drawing
  • US11646995B2 patent drawing
  • US11646995B2 patent drawing

AI summary

This disclosure describes methods to distribute intrusion detection in a network across multiple devices in the network, such as across routing/switching or other infrastructure devices. For example, as a packet is routed through a network infrastructure, an overlay mechanism may be utilized to indicate which of a total set of intrusion detection rules have been applied to the packet. Each infrastructure device may evaluate which rules have already been applied to the packet, using a result of the evaluation to determine where to route the packet in the network infrastructure for application of additional intrusion detection rules. Additionally, each infrastructure device may record a result of its application of the portion of intrusion detection rules directly into the packet.