Shared MAC Blocking for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for addressing denial-of-service attacks in complex networks are ineffective in guaranteeing immediate cessation of attacks and preventing future occurrences, as they rely on identifying and blocking the aggressor, which does not ensure long-term security.
Innovation Solution
Implementing a collaborative methodology among network management units to share and block Media Access Control (MAC) addresses of offending devices, allowing for coordinated blocking across multiple Internet Service Providers (ISPs) to prevent access to the network, thereby addressing the root of the attack and preventing recurrence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional identification and blocking methods are used, then the attack source can be identified, but the attack cannot be guaranteed to cease and may recur
Solution Approach 1:
The patent merges multiple network management processors from different ISPs into a collaborative MAC blocking system. When an offense is detected, the offending MAC address is shared across the network hierarchy, enabling coordinated blocking actions by multiple processors simultaneously, thereby ensuring comprehensive attack cessation and preventing recurrence through network-wide enforcement
2Reliability
If MAC addresses are shared and blocked across multiple ISPs, then offending devices are prevented from reattacking, but the network coordination complexity increases
Solution Approach 1:
The patent segments the network management function into hierarchical levels (higher hierarchical order processors and lower hierarchical order processors). Each processor operates within its segment but can share MAC address information across segments. This segmentation allows complex network-wide coordination to be managed through simplified local actions at each hierarchical level, reducing overall system complexity while maintaining effective attack prevention
Data Source
AI summary
For enhancing security in a complex network by a computer processor device, a processor collaborates with at least one additional processor device in a higher hierarchical order in the complex network. A Media Access Control (MAC) address of an offending network device is shared between the processor devices such that access of the offending network device to portions of the complex network under the supervisory control of the processor devices may be subsequently blocked.


