Shared MAC Blocking for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for addressing denial-of-service attacks in complex networks are ineffective in guaranteeing immediate cessation of attacks and preventing future occurrences, as they rely on identifying and blocking the aggressor, which does not ensure long-term security.

Innovation Solution

Implementing a collaborative methodology among network management units to share and block Media Access Control (MAC) addresses of offending devices, allowing for coordinated blocking across multiple Internet Service Providers (ISPs) to prevent access to the network, thereby addressing the root of the attack and preventing recurrence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional identification and blocking methods are used, then the attack source can be identified, but the attack cannot be guaranteed to cease and may recur

Engineering Contradiction:
Improveattack source identification accuracyVSAvoidattack cessation guarantee
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent merges multiple network management processors from different ISPs into a collaborative MAC blocking system. When an offense is detected, the offending MAC address is shared across the network hierarchy, enabling coordinated blocking actions by multiple processors simultaneously, thereby ensuring comprehensive attack cessation and preventing recurrence through network-wide enforcement

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If MAC addresses are shared and blocked across multiple ISPs, then offending devices are prevented from reattacking, but the network coordination complexity increases

Engineering Contradiction:
Improveattack prevention effectivenessVSAvoidnetwork coordination structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network management function into hierarchical levels (higher hierarchical order processors and lower hierarchical order processors). Each processor operates within its segment but can share MAC address information across segments. This segmentation allows complex network-wide coordination to be managed through simplified local actions at each hierarchical level, reducing overall system complexity while maintaining effective attack prevention

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10057290B2Shared MAC blocking
Publication Date: 2018.08.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10057290B2 patent drawing
  • US10057290B2 patent drawing
  • US10057290B2 patent drawing

AI summary

For enhancing security in a complex network by a computer processor device, a processor collaborates with at least one additional processor device in a higher hierarchical order in the complex network. A Media Access Control (MAC) address of an offending network device is shared between the processor devices such that access of the offending network device to portions of the complex network under the supervisory control of the processor devices may be subsequently blocked.