Smart NIC and EPP Integration for Automated Host Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies face difficulties in isolating hosts, virtual machines, or containers with security issues from networks, as manual processes are required, and there is a lack of direct communication between end-point-protection platforms and network interface devices for security-related signals.
Innovation Solution
Integration of smart Network Interface Controllers (NICs) and End-Point-Protection Platforms (EPPs) enables automated signaling to isolate or protect hosts, virtual machines, and containers by exchanging security and network-related events, allowing for automated protection mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual isolation processes are used to separate hosts with security issues from networks, then security isolation can be achieved, but the operation complexity increases and response time is delayed
Solution Approach 1:
The system enables automated security isolation where the network interface device autonomously responds to security threats without requiring manual human intervention. The EPP detects security issues and automatically triggers isolation actions through integrated communication channels, allowing the system to self-manage security incidents.
Solution Approach 2:
The patent establishes a feedback loop where the EPP continuously monitors security states and communicates with network interface devices. When security threats are detected, the EPP sends automated signals back to the network interface device to execute isolation actions, creating a closed-loop control system for security response.
2Extent of automation
If automated signaling between smart NICs and EPPs is implemented, then response speed and automation level improve, but device complexity increases
Solution Approach 1:
The patent merges the EPP software module with the network interface device to create an integrated security system. This combination allows direct communication and coordinated action between security monitoring and network control functions, reducing the need for complex external signaling while maintaining high automation levels.
Solution Approach 2:
The network interface device is designed with multi-functionality, serving both as a network communication interface and as a security response execution unit. This universal design allows the same device to handle both data transmission and security isolation actions, reducing system complexity while enabling automated responses.
3Reliability
If physical disconnection is used to isolate compromised hosts, then security isolation is effective, but network disruption and loss of legitimate traffic occur
Solution Approach 1:
The patent applies segmentation by isolating only the specific virtual machine or container exhibiting security issues rather than disconnecting the entire physical host. This granular segmentation allows the compromised virtual environment to be separated while leaving other virtual machines and containers on the same physical host unaffected, maintaining network connectivity for legitimate traffic.
Solution Approach 2:
The network interface device acts as an intermediary that can selectively block or redirect traffic from compromised virtual machines without physically disconnecting the host. This intermediary mechanism allows precise control over which traffic is isolated, enabling security responses that minimize disruption to legitimate network communications.
Data Source
Figure 1
Figure 2
AI summary
Described are devices, systems, and methods for improving network security by providing network interface devices communicatively coupled to end-point-protection platforms (EPP) based on integration of two different technologies (e.g., smart NICs and EPP software) allowing each to automatically signal the other and implement automated protection mechanisms to isolate or protect a host, a virtual machine, and/or a container.