Switching Device Packet Copy for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion Detection Systems (IDS) implemented on separate servers from switching devices in communications networks face limitations in processing capability and bandwidth, leading to difficulties in detecting anomalies and requiring additional hardware, which increases cost and complexity, and limits the ability to aggregate data across multiple switching devices.

Innovation Solution

A switching device with an interface that copies and analyzes packets to detect anomalies, forwarding relevant information to an IDS within the network, while setting limits on packet forwarding to prevent overload, thereby enhancing IDS processing capability and reducing hardware requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IDS is implemented on a separate server attached to the communications network, then intrusion detection functionality is provided, but bandwidth limitations and processing capability limitations prevent effective detection and network growth

Engineering Contradiction:
Improveintrusion detection effectivenessVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines the IDS functionality with the network switch by integrating a packet copier and anomaly detector directly into the switch architecture. This merging eliminates the need for separate IDS servers and their limited bandwidth connections, allowing the IDS to process packets at line rate without becoming a bottleneck to network throughput.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a packet copier as an intermediary component within the switch that creates copies of packets for IDS analysis without interfering with the main packet forwarding path. This mediator allows simultaneous intrusion detection and normal network traffic flow, resolving the contradiction between detection effectiveness and network throughput.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If IDS boards are implemented on network switches and routers, then processing capability is improved, but physical space requirements and hardware cost increase

Engineering Contradiction:
ImproveIDS processing capabilityVSAvoidhardware requirements
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent makes the network switch multi-functional by enabling it to perform both its traditional packet forwarding function and IDS functions simultaneously. The switch's existing packet processing infrastructure is leveraged to provide intrusion detection, eliminating the need for separate dedicated IDS hardware and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The network switch provides intrusion detection services for itself and other network devices by integrating the IDS functionality directly into its architecture. This self-service approach eliminates the need for external IDS hardware, reducing physical space requirements and hardware costs while maintaining high processing capability.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple IDS servers are deployed to handle increased network traffic, then detection coverage is improved, but cost and system complexity increase

Engineering Contradiction:
Improvedetection coverageVSAvoidnumber of IDS servers
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the IDS functionality from the traditional server-based architecture and distributes it across multiple network switches throughout the network. Each switch independently performs packet copying and anomaly detection for its local traffic, providing comprehensive detection coverage without requiring centralized IDS servers and their associated complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7849506B1Switching device, method, and computer program for efficient intrusion detection
Publication Date: 2010.12.07 PULSELINK SYSTEMS LLC
  • US7849506B1 patent drawing
  • US7849506B1 patent drawing
  • US7849506B1 patent drawing

AI summary

A switching device, method, and computer program utilizes a copy technique to detect unauthorized access to a communications network. An interface of the switching device is connected to receive an original packet and copy the original packet to create a copied packet. A processor within the switching device is operable to analyze information related to the original packet or the copied packet to detect an anomaly related to the original packet or the copied packet. The processor is further operable to cause the copied packet to be forwarded to an intrusion detection system within the communications network upon detecting the anomaly.