Network Switch Traffic Mirroring for Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems rely on signature-based techniques, which are ineffective against unknown threats and Day-Zero attacks, and often become bottlenecks or points of failure when deployed in-line with the network.
Innovation Solution
A network switch employs dynamic policy rules to detect and mitigate threats by mirroring suspicious traffic to a security management device, which determines the source and destination of the threat and builds a policy to redirect and block harmful traffic, using CLEAR-Flow technology and XML API for real-time enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If signature-based security techniques are used to detect network threats, then known threats can be prevented or mitigated, but unknown threats and Day-Zero attacks cannot be detected
Solution Approach 1:
The patent implements dynamic policy rules that automatically adapt to new threat patterns by continuously analyzing network traffic flows. The system dynamically creates, modifies, and deletes policy rules based on real-time traffic analysis, enabling detection of both known and unknown threats without relying on static signature databases.
Solution Approach 2:
The security management device performs self-learning by automatically analyzing mirrored network traffic, identifying threat patterns, and generating new policy rules without human intervention. The system serves itself by autonomously updating its detection capabilities based on observed traffic patterns.
2Reliability
If network security systems are deployed in-line with the network to mitigate threats, then threats can be blocked, but the system becomes a bottleneck or point of failure
Solution Approach 1:
The patent introduces a security management device that receives mirrored copies of network traffic through an intermediary mechanism (traffic mirroring). This allows the security device to analyze and mitigate threats without being placed in-line with the primary network data path, thus avoiding bottlenecks while maintaining threat blocking capability.
Solution Approach 2:
The system segments network traffic handling into two separate paths: the primary network data path for high-speed throughput, and a mirrored traffic path for security analysis. This segmentation allows security processing to occur parallel to data transmission without impeding network performance.
3Reliability
If network security systems are deployed in-line with the network to mitigate threats, then threats can be blocked, but the system introduces latency and single point of failure risks
Solution Approach 1:
By using traffic mirroring as an intermediary mechanism, the security management device processes copied traffic packets rather than inspecting every packet in the primary data path. This intermediary approach eliminates the latency introduced by in-line inspection while maintaining the ability to block threats.
Solution Approach 2:
The system applies security analysis only to mirrored copies of traffic packets that are suspected of containing threats, rather than inspecting every single packet. This partial action approach reduces the time overhead while still achieving effective threat mitigation.
Data Source
AI summary
A network switch automatically detects undesired network traffic and mirrors the undesired traffic to a security management device. The security management device determines the source of the undesired traffic and redirects traffic from the source to itself. The security management device also automatically sends a policy to a switch to block traffic from the source.


