Redirected Firewall Discovery for Encrypted Botnet Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies struggle to detect and manage botnets, especially those using encryption protocols, which can masquerade as normal web traffic, leading to undetected infections and exploitation of host computers.

Innovation Solution

A system and method for redirected firewall discovery in a network environment, where a firewall maintains a list of managed hosts and uses metadata channels with authentication to redirect and identify valid firewalls, employing ICMP packets with HMACs or encrypted hashes to ensure data integrity and authenticity, allowing for dynamic information sharing and granular control of network flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall discovery methods are used, then network security monitoring is simplified, but encrypted botnet traffic cannot be detected or differentiated from normal web traffic

Engineering Contradiction:
Improvebotnet detection accuracyVSAvoidfirewall identification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary firewall discovery and authentication before botnet detection. Firewalls are pre-identified and authenticated using HMACs or encrypted hashes, creating a trusted baseline of legitimate firewalls. This preliminary action enables subsequent reliable detection of botnet traffic by comparing against the authenticated firewall list, resolving the contradiction between detection accuracy and system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using HMACs or encrypted hashes that mediate between the host and firewall. This intermediary layer provides verifiable authentication without requiring complex inspection of encrypted botnet traffic, enabling reliable botnet detection while maintaining manageable system complexity through standardized authentication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encrypted protocols are used to protect network traffic, then data confidentiality is improved, but firewall discovery and botnet detection become impossible

Engineering Contradiction:
Improvedata confidentialityVSAvoidfirewall identification difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system segments network traffic into two categories: authentication traffic that remains unencrypted or uses lightweight HMACs for firewall discovery, and data traffic that uses full encryption for confidentiality. This segmentation allows firewall identification to occur in the unencrypted segment while data confidentiality is maintained in the encrypted segment, resolving the contradiction between detectability and confidentiality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary authentication layer using HMACs or encrypted hashes is introduced that operates separately from the encrypted data channel. This intermediary provides the necessary authentication and firewall discovery functionality without compromising the confidentiality of the encrypted data channel, allowing both goals to coexist.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive network flow inspection is performed, then botnet detection capability is improved, but network performance and processing speed deteriorate

Engineering Contradiction:
Improvebotnet detection capabilityVSAvoidnetwork processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication and firewall identification using lightweight HMACs or encrypted hashes before full botnet detection inspection. This preliminary action filters and pre-authenticates traffic, allowing subsequent botnet detection to focus only on authenticated flows, thereby maintaining high detection capability while reducing overall processing overhead and preserving network performance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10652210B2System and method for redirected firewall discovery in a network environment
Publication Date: 2020.05.12 MCAFEE LLC
  • US10652210B2 patent drawing
  • US10652210B2 patent drawing
  • US10652210B2 patent drawing

AI summary

A method is provided in one example embodiment that includes receiving metadata from a host over a metadata channel. The metadata may be correlated with a network flow and a network policy may be applied to the connection. In other embodiments, a network flow may be received from a host without metadata associated with the flow, and a discovery redirect may be sent to the host. Metadata may then be received and correlated with the flow to identify a network policy action to apply to the flow.