SASE-Based Hierarchical Filtering for Wireless Mesh Exhaustion Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless mesh networks face challenges in efficiently managing unauthorized network traffic, which can exhaust bandwidth and processing resources due to compromised nodes sending attack traffic, particularly when utilizing border routers with limited processing capacity.
Innovation Solution
Implementing a hierarchical network traffic filtering scheme using Software-Defined Field Area Network (SD-FAN) and fog computing, where edge routers (fog devices) with enhanced processing capacity apply complex filtering policies, while nodes with limited capacity perform basic filtering, directing suspicious traffic to fog devices for further analysis, optimizing resource and bandwidth usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If border routers with limited processing capacity are used to filter network traffic, then network security is improved, but processing resources are exhausted by unauthorized traffic
Solution Approach 1:
The patent segments the traffic filtering function across multiple network nodes (border routers, intermediate routers, and core network) rather than concentrating it at the border router. Different types of filtering (basic vs. advanced) are applied at different locations in the network path, distributing the processing load and preventing resource exhaustion at any single point.
Solution Approach 2:
The patent introduces an intermediary mechanism where intermediate routers and the core network act as mediators to handle advanced filtering of suspicious traffic. This relieves the border router from processing all traffic extensively, allowing it to focus on basic filtering while more resource-intensive analysis is performed by intermediaries further down the network path.
2Measurement precision
If complex filtering policies are applied at all nodes, then unauthorized traffic detection is improved, but processing capacity requirements increase
Solution Approach 1:
The patent applies different levels of filtering complexity at different network locations based on local capabilities. Border routers with limited capacity perform basic filtering, while the core network with greater resources performs advanced filtering. This local quality approach ensures high detection precision without requiring all nodes to have high processing capacity.
Solution Approach 2:
The patent implements a two-stage filtering approach where basic filtering is applied universally at all nodes, and advanced filtering is applied selectively to suspicious traffic at the core network. This partial action approach achieves high detection precision for unauthorized traffic without requiring excessive processing capacity at every node.
3Reliability
If all network traffic is forwarded to border router for analysis, then security monitoring is improved, but bandwidth consumption increases
Solution Approach 1:
The patent extracts the advanced filtering function from the border router and relocates it to the core network. This separation allows the border router to forward only basic-filtered traffic, while the core network handles advanced analysis of suspicious packets. This extraction reduces bandwidth consumption on the border router connection while maintaining comprehensive security monitoring.
Solution Approach 2:
The patent applies preliminary basic filtering at the border router before forwarding traffic to the core network. This preliminary action eliminates obviously unauthorized traffic early in the path, reducing the volume of traffic that requires advanced filtering and thus reducing overall bandwidth consumption while maintaining security monitoring effectiveness.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
The present disclosure provides a hierarchical method of identifying unauthorized network traffic in a network by applying, at one of a first plurality of nodes of a network, a first level of network traffic analysis to identify received network traffic as one of authorized or suspicious network traffic, the one of the first plurality of nodes having a first path for traffic routing and a second path to one of a second plurality of nodes of the network, the second path used for forwarding the suspicious network traffic to the one of the second plurality of nodes; tagging the received network traffic as the suspicious network traffic; and sending the suspicious network traffic to the one of the second plurality of nodes over the second path, the second network node applying a second level of network analysis to determine if the received network traffic is authorized, unauthorized or remains suspicious.