Smart NIC and EPP Integration for Automated Host Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face difficulties in isolating hosts, virtual machines, or containers with security issues from networks, as manual processes are required, and there is a lack of direct communication between end-point-protection platforms and network interface devices for security-related signals.

Innovation Solution

Integration of smart Network Interface Controllers (NICs) and End-Point-Protection Platforms (EPPs) enables automated signaling to isolate or protect hosts, virtual machines, and containers by exchanging security and network-related events, allowing for automated protection mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual isolation processes are used to separate hosts with security issues from networks, then security isolation can be achieved, but the operation complexity increases and response time is delayed

Engineering Contradiction:
Improvesecurity isolationVSAvoidmanual process complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automated security isolation where the network interface device autonomously responds to security threats without requiring manual human intervention. The EPP detects security issues and automatically triggers isolation actions through integrated communication channels, allowing the system to self-manage security incidents.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes a feedback loop where the EPP continuously monitors security states and communicates with network interface devices. When security threats are detected, the EPP sends automated signals back to the network interface device to execute isolation actions, creating a closed-loop control system for security response.

Inventive Principle:
Principle #23Feedback

2Extent of automation

If automated signaling between smart NICs and EPPs is implemented, then response speed and automation level improve, but device complexity increases

Engineering Contradiction:
Improveautomated security responseVSAvoidintegration complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent merges the EPP software module with the network interface device to create an integrated security system. This combination allows direct communication and coordinated action between security monitoring and network control functions, reducing the need for complex external signaling while maintaining high automation levels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network interface device is designed with multi-functionality, serving both as a network communication interface and as a security response execution unit. This universal design allows the same device to handle both data transmission and security isolation actions, reducing system complexity while enabling automated responses.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If physical disconnection is used to isolate compromised hosts, then security isolation is effective, but network disruption and loss of legitimate traffic occur

Engineering Contradiction:
Improvesecurity isolation effectivenessVSAvoidnetwork disruption
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies segmentation by isolating only the specific virtual machine or container exhibiting security issues rather than disconnecting the entire physical host. This granular segmentation allows the compromised virtual environment to be separated while leaving other virtual machines and containers on the same physical host unaffected, maintaining network connectivity for legitimate traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network interface device acts as an intermediary that can selectively block or redirect traffic from compromised virtual machines without physically disconnecting the host. This intermediary mechanism allows precise control over which traffic is isolated, enabling security responses that minimize disruption to legitimate network communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3476101B1Method, device and system for network security
Publication Date: 2023.10.25 PENSANDO SYSTEMS INC
  • EP3476101B1 patent drawingFigure 1
  • EP3476101B1 patent drawingFigure 2

AI summary

Described are devices, systems, and methods for improving network security by providing network interface devices communicatively coupled to end-point-protection platforms (EPP) based on integration of two different technologies (e.g., smart NICs and EPP software) allowing each to automatically signal the other and implement automated protection mechanisms to isolate or protect a host, a virtual machine, and/or a container.