Redirected Firewall Discovery for Encrypted Botnet Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security technologies struggle to detect and manage botnets, especially those using encryption protocols, which can masquerade as normal web traffic, leading to undetected infections and exploitation of host computers.
Innovation Solution
A system and method for redirected firewall discovery in a network environment, where a firewall maintains a list of managed hosts and uses metadata channels with authentication to redirect and identify valid firewalls, employing ICMP packets with HMACs or encrypted hashes to ensure data integrity and authenticity, allowing for dynamic information sharing and granular control of network flows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall discovery methods are used, then network security monitoring is simplified, but encrypted botnet traffic cannot be detected or differentiated from normal web traffic
Solution Approach 1:
The system performs preliminary firewall discovery and authentication before botnet detection. Firewalls are pre-identified and authenticated using HMACs or encrypted hashes, creating a trusted baseline of legitimate firewalls. This preliminary action enables subsequent reliable detection of botnet traffic by comparing against the authenticated firewall list, resolving the contradiction between detection accuracy and system complexity.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using HMACs or encrypted hashes that mediate between the host and firewall. This intermediary layer provides verifiable authentication without requiring complex inspection of encrypted botnet traffic, enabling reliable botnet detection while maintaining manageable system complexity through standardized authentication protocols.
2Reliability
If encrypted protocols are used to protect network traffic, then data confidentiality is improved, but firewall discovery and botnet detection become impossible
Solution Approach 1:
The system segments network traffic into two categories: authentication traffic that remains unencrypted or uses lightweight HMACs for firewall discovery, and data traffic that uses full encryption for confidentiality. This segmentation allows firewall identification to occur in the unencrypted segment while data confidentiality is maintained in the encrypted segment, resolving the contradiction between detectability and confidentiality.
Solution Approach 2:
An intermediary authentication layer using HMACs or encrypted hashes is introduced that operates separately from the encrypted data channel. This intermediary provides the necessary authentication and firewall discovery functionality without compromising the confidentiality of the encrypted data channel, allowing both goals to coexist.
3Reliability
If comprehensive network flow inspection is performed, then botnet detection capability is improved, but network performance and processing speed deteriorate
Solution Approach 1:
The system performs preliminary authentication and firewall identification using lightweight HMACs or encrypted hashes before full botnet detection inspection. This preliminary action filters and pre-authenticates traffic, allowing subsequent botnet detection to focus only on authenticated flows, thereby maintaining high detection capability while reducing overall processing overhead and preserving network performance.
Data Source
AI summary
A method is provided in one example embodiment that includes receiving metadata from a host over a metadata channel. The metadata may be correlated with a network flow and a network policy may be applied to the connection. In other embodiments, a network flow may be received from a host without metadata associated with the flow, and a discovery redirect may be sent to the host. Metadata may then be received and correlated with the flow to identify a network policy action to apply to the flow.


