Quarantined Network Edge Traffic Routing for Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network edge systems face a heavy burden in processing communication traffic due to resource-intensive tasks like identifying and handling malicious traffic, which can lead to malicious traffic accessing the network despite prevention efforts, as they operate within the same network space as non-malicious traffic.
Innovation Solution
Implementing a specialized network edge system that offloads potentially malicious traffic for more intensive processing, using criteria-based routing to segregate and quarantine such traffic, potentially utilizing a virtualized computing element within a quarantined software-defined network to perform deep packet inspection without overburdening the initial edge system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If edge systems perform resource-intensive processing to identify and handle malicious traffic, then network security is improved, but the processing burden on edge systems increases and may lead to system overload
Solution Approach 1:
The patent extracts the resource-intensive malicious traffic processing function from conventional edge systems and relocates it to a specialized security edge system. This separation allows conventional edge systems to maintain their primary routing and forwarding functions with reduced processing burden, while the specialized system handles the computationally demanding tasks of deep packet inspection and malicious traffic analysis, thereby resolving the contradiction between security reliability and processing productivity
Solution Approach 2:
The patent introduces a specialized security edge system as an intermediary component between conventional edge systems and the core network. This intermediary system receives traffic information from conventional edge systems, performs resource-intensive security processing, and returns processing results. The intermediary architecture allows security processing to be performed without directly burdening the conventional edge systems, resolving the contradiction between performing intensive security checks and maintaining processing capacity
2Ease of operation
If malicious traffic is processed in the same network space as non-malicious traffic, then traffic flow is simplified, but malicious traffic may gain access to the network despite prevention efforts
Solution Approach 1:
The patent segments the network edge into conventional edge systems and a specialized security edge system with distinct functions. Conventional edge systems handle routing and forwarding, while the specialized security edge system handles security processing in isolation. This segmentation allows malicious traffic to be identified and contained in a separate processing domain, preventing it from mixing with non-malicious traffic and gaining network access, while maintaining simplified traffic flow through clear functional boundaries
Solution Approach 2:
The specialized security edge system acts as an intermediary that processes traffic information from conventional edge systems before traffic enters the core network. This intermediary performs security checks and isolates malicious traffic in a separate processing path, preventing contamination of the main network traffic flow. The intermediary architecture maintains ease of operation by using standardized information exchange interfaces while ensuring security through isolated processing of potentially malicious traffic
Data Source
AI summary
Embodiments disclosed herein provide systems and methods for quarantining communications at a network edge by routing traffic through a specialized network edge system. In a particular embodiment a method provides, identifying criteria indicating whether certain network traffic should be handled by the specialized network edge system. The method further provides receiving first information about first network traffic received at a first network edge system for a communication network. In response to determining, based on the first information, that the first network traffic satisfies the criteria, the method provides routing the first network traffic through the specialized network edge system.


