Time-Based Anti-Replay Window Adaptation for QoS Reordering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In software-defined wide area networks (SD-WANs), IPSec encapsulated packets can be forwarded out of sequence and dropped during congestion due to varying Quality of Service (QoS) policies, necessitating a fixed anti-replay window size that fails to accommodate diverse network conditions and security attack risks.
Innovation Solution
A network node dynamically adjusts the time-based anti-replay window size based on sequence-based, time-based, and selective anti-replay checks, using anti-replay engines to detect packet duplication and adapt the window size according to network conditions, thereby mitigating security risks and optimizing QoS deployment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a fixed anti-replay window size is used, then security protection is provided, but the system cannot adapt to diverse network conditions and QoS policies
Solution Approach 1:
The patent implements dynamic adjustment of the anti-replay window size based on real-time network conditions. The system monitors packet arrival patterns, sequence numbers, and timing information to automatically resize the window, transitioning from a static fixed-size approach to a dynamic adaptive mechanism that responds to changing network states and QoS requirements
Solution Approach 2:
The system changes the parameter of anti-replay window size based on observed network conditions. By monitoring packet timing, sequence continuity, and network congestion levels, the system adjusts the window size parameter to optimize both security protection and compatibility with diverse QoS policies, allowing legitimate out-of-sequence packets to pass while maintaining replay attack detection
2Productivity
If QoS policies prioritize packets based on forwarding class, then bandwidth management is improved, but packets may be forwarded out of sequence and dropped by anti-replay checks
Solution Approach 1:
The anti-replay window size is dynamically adjusted to accommodate QoS-induced packet reordering. When network monitoring detects out-of-sequence arrivals consistent with QoS policy operation, the system expands the window to include these legitimate packets, preventing unnecessary drops while maintaining protection against replay attacks that exhibit different patterns
Solution Approach 2:
The system implements feedback mechanisms that monitor packet arrival patterns and sequence continuity. When QoS policies cause out-of-sequence forwarding, the feedback loop detects this pattern and adjusts the anti-replay window accordingly, allowing the system to adapt to the reordering while maintaining reliability for legitimate traffic
3Reliability
If the anti-replay window size is increased to accommodate out-of-sequence packets, then packet delivery is improved, but security protection against replay attacks is weakened
Solution Approach 1:
The system dynamically adjusts the anti-replay window size based on real-time analysis of packet patterns. Rather than using a permanently large window that would weaken security, the system expands the window only when and where QoS-induced reordering is detected, and maintains a smaller window size during normal conditions to preserve strong replay attack protection
Solution Approach 2:
The system applies different anti-replay window sizes to different traffic flows or time periods based on local network conditions. Legitimate QoS-affected flows receive accommodative window sizing, while maintaining strict replay protection for other traffic, thereby achieving both reliability improvement and security preservation through localized adaptation
Data Source
AI summary
In one embodiment, a method includes receiving, by a network node, a packet associated with a session. The method also includes performing, by the network node, a sequence-based anti-replay check and determining, by the network node, that the sequence-based anti-replay check rejected the packet. The method further includes performing, by the network node, a time-based anti-replay check, performing, by the network node, a selective anti-replay check, and determining, by the network node, whether to dynamically adjust a time-based anti-replay window size.


