Threat Response in Multi-Router Networks via Unified Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing and configuring branch routers across a network with multiple providers is cumbersome due to the need for unique commands for each provider, complicating threat response and network security in a multi-router environment.
Innovation Solution
A method is implemented to identify threats by IP address, generate routing update packets to block communications, and communicate these packets to routers using established routing protocol sessions, thereby updating access control lists without requiring unique commands for each hardware provider.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional router configuration methods are used with provider-specific commands, then each router can be configured individually, but the management complexity increases significantly in multi-router environments with multiple providers
Solution Approach 1:
The patent introduces a controller as an intermediary device that mediates between the user and multiple routers from different providers. The controller translates high-level configuration instructions into provider-specific commands, eliminating the need for users to manage multiple command sets directly. This intermediary layer simplifies the configuration process while handling the complexity of provider-specific protocols internally.
Solution Approach 2:
The controller is designed with multi-functionality to support configuration of routers from multiple different providers through a single unified interface. It implements multiple translation layers and command mappings that enable universal configuration capabilities across heterogeneous router devices, allowing one system to perform what previously required multiple specialized tools.
2Productivity
If provider-specific configuration commands are used for each router, then accurate control over each router is achieved, but the time required to update configurations across multiple routers increases
Solution Approach 1:
The controller pre-loads and caches provider-specific command templates and translation rules before configuration updates are needed. When a configuration change is requested, the controller retrieves pre-prepared command sequences from its cache rather than generating them in real-time, significantly reducing the time required to push updates across multiple routers. This preliminary preparation of configuration templates enables rapid deployment.
Solution Approach 2:
The patent combines multiple provider-specific configuration operations into a single unified configuration action through the controller. Instead of executing separate configuration commands for each router sequentially, the controller batches and consolidates these operations, translating and pushing multiple configuration updates in parallel or near-simultaneous fashion, thereby reducing total update time while maintaining accurate control over each individual router.
3Reliability
If manual configuration updates are performed on each router individually, then precise control over router settings is maintained, but the effort and complexity of managing branch routers across the network increases
Solution Approach 1:
The controller serves as a smart intermediary that receives high-level configuration intent from administrators and automatically translates it into precise, provider-specific configuration commands for each router. This maintains configuration control accuracy by ensuring each router receives the correct specialized commands, while simultaneously reducing management effort by eliminating the need for administrators to manually craft and manage provider-specific syntax for each device.
Solution Approach 2:
The controller implements self-service capabilities by automatically adapting configuration commands to match the specific requirements of each router provider based on router identification. When a router is added to the network, the controller autonomously determines the appropriate provider protocol, loads the corresponding command templates, and configures the router without human intervention, thereby maintaining precision while dramatically reducing the operational effort required.
Data Source
AI summary
Systems, methods, and software to implement network configuration updates in a computing network. In one implementation, a method includes identifying a threat related to an internet protocol (IP) address, wherein the IP address corresponds to a computing node in the computing network. After identifying the threat, the method further includes generates one or more routing update packets that indicate a block request for at least the IP address. Once generated, the method also provides communicating the one or more routing update packets to one or more routers in the computing network.


