Network Switch Traffic Mirroring for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems rely on signature-based techniques, which are ineffective against unknown threats and Day-Zero attacks, and often become bottlenecks or points of failure when deployed in-line with the network.

Innovation Solution

A network switch employs dynamic policy rules to detect and mitigate threats by mirroring suspicious traffic to a security management device, which determines the source and destination of the threat and builds a policy to redirect and block harmful traffic, using CLEAR-Flow technology and XML API for real-time enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based security techniques are used to detect network threats, then known threats can be prevented or mitigated, but unknown threats and Day-Zero attacks cannot be detected

Engineering Contradiction:
Improvethreat detection effectivenessVSAvoidcapability to detect unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic policy rules that automatically adapt to new threat patterns by continuously analyzing network traffic flows. The system dynamically creates, modifies, and deletes policy rules based on real-time traffic analysis, enabling detection of both known and unknown threats without relying on static signature databases.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security management device performs self-learning by automatically analyzing mirrored network traffic, identifying threat patterns, and generating new policy rules without human intervention. The system serves itself by autonomously updating its detection capabilities based on observed traffic patterns.

Inventive Principle:
Principle #25Self-service

2Reliability

If network security systems are deployed in-line with the network to mitigate threats, then threats can be blocked, but the system becomes a bottleneck or point of failure

Engineering Contradiction:
Improvethreat mitigation capabilityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a security management device that receives mirrored copies of network traffic through an intermediary mechanism (traffic mirroring). This allows the security device to analyze and mitigate threats without being placed in-line with the primary network data path, thus avoiding bottlenecks while maintaining threat blocking capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments network traffic handling into two separate paths: the primary network data path for high-speed throughput, and a mirrored traffic path for security analysis. This segmentation allows security processing to occur parallel to data transmission without impeding network performance.

Inventive Principle:
Principle #1Segmentation

3Reliability

If network security systems are deployed in-line with the network to mitigate threats, then threats can be blocked, but the system introduces latency and single point of failure risks

Engineering Contradiction:
Improvethreat mitigation capabilityVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By using traffic mirroring as an intermediary mechanism, the security management device processes copied traffic packets rather than inspecting every packet in the primary data path. This intermediary approach eliminates the latency introduced by in-line inspection while maintaining the ability to block threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies security analysis only to mirrored copies of traffic packets that are suspected of containing threats, rather than inspecting every single packet. This partial action approach reduces the time overhead while still achieving effective threat mitigation.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8255996B2Network threat detection and mitigation
Publication Date: 2012.08.28 EXTREME NETWORKS INC
  • US8255996B2 patent drawing
  • US8255996B2 patent drawing
  • US8255996B2 patent drawing

AI summary

A network switch automatically detects undesired network traffic and mirrors the undesired traffic to a security management device. The security management device determines the source of the undesired traffic and redirects traffic from the source to itself. The security management device also automatically sends a policy to a switch to block traffic from the source.