SASE-Based Hierarchical Filtering for Wireless Mesh Exhaustion Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless mesh networks face challenges in efficiently managing unauthorized network traffic, which can exhaust bandwidth and processing resources due to compromised nodes sending attack traffic, particularly when utilizing border routers with limited processing capacity.

Innovation Solution

Implementing a hierarchical network traffic filtering scheme using Software-Defined Field Area Network (SD-FAN) and fog computing, where edge routers (fog devices) with enhanced processing capacity apply complex filtering policies, while nodes with limited capacity perform basic filtering, directing suspicious traffic to fog devices for further analysis, optimizing resource and bandwidth usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If border routers with limited processing capacity are used to filter network traffic, then network security is improved, but processing resources are exhausted by unauthorized traffic

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the traffic filtering function across multiple network nodes (border routers, intermediate routers, and core network) rather than concentrating it at the border router. Different types of filtering (basic vs. advanced) are applied at different locations in the network path, distributing the processing load and preventing resource exhaustion at any single point.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where intermediate routers and the core network act as mediators to handle advanced filtering of suspicious traffic. This relieves the border router from processing all traffic extensively, allowing it to focus on basic filtering while more resource-intensive analysis is performed by intermediaries further down the network path.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If complex filtering policies are applied at all nodes, then unauthorized traffic detection is improved, but processing capacity requirements increase

Engineering Contradiction:
Improveunauthorized traffic detectionVSAvoidprocessing capacity requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies different levels of filtering complexity at different network locations based on local capabilities. Border routers with limited capacity perform basic filtering, while the core network with greater resources performs advanced filtering. This local quality approach ensures high detection precision without requiring all nodes to have high processing capacity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements a two-stage filtering approach where basic filtering is applied universally at all nodes, and advanced filtering is applied selectively to suspicious traffic at the core network. This partial action approach achieves high detection precision for unauthorized traffic without requiring excessive processing capacity at every node.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If all network traffic is forwarded to border router for analysis, then security monitoring is improved, but bandwidth consumption increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the advanced filtering function from the border router and relocates it to the core network. This separation allows the border router to forward only basic-filtered traffic, while the core network handles advanced analysis of suspicious packets. This extraction reduces bandwidth consumption on the border router connection while maintaining comprehensive security monitoring.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies preliminary basic filtering at the border router before forwarding traffic to the core network. This preliminary action eliminates obviously unauthorized traffic early in the path, reducing the volume of traffic that requires advanced filtering and thus reducing overall bandwidth consumption while maintaining security monitoring effectiveness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4424041B1SASE based method of preventing exhausting attack in wireless mesh networks
Publication Date: 2025.09.10 CISCO TECHNOLOGY INC
  • EP4424041B1 patent drawingFigure 1A
  • EP4424041B1 patent drawingFigure 1B
  • EP4424041B1 patent drawingFigure 2

AI summary

The present disclosure provides a hierarchical method of identifying unauthorized network traffic in a network by applying, at one of a first plurality of nodes of a network, a first level of network traffic analysis to identify received network traffic as one of authorized or suspicious network traffic, the one of the first plurality of nodes having a first path for traffic routing and a second path to one of a second plurality of nodes of the network, the second path used for forwarding the suspicious network traffic to the one of the second plurality of nodes; tagging the received network traffic as the suspicious network traffic; and sending the suspicious network traffic to the one of the second plurality of nodes over the second path, the second network node applying a second level of network analysis to determine if the received network traffic is authorized, unauthorized or remains suspicious.