Virtual Switch Threat Detection Engine for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network operators face challenges in quickly and efficiently responding to threats from virtual network functions (VNFs) in virtualized environments, as existing monitoring systems often fail to adapt quickly to newly created and evolving threats, leading to potential rapid spread of threats across networks.

Innovation Solution

A centralized threat aware controller embedded with a threat detection engine within virtual network switches provides internal monitoring and updates threat feeds, initiating threat analysis VNFs for suspected traffic, and coordinating with external threat information feeds to detect and isolate malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a centralized threat aware controller with embedded threat detection engine is deployed in virtual network switches, then threat detection speed and response efficiency are improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvethreat detection speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The threat detection engine is embedded within the virtual network switch, creating a nested architecture where the detection engine operates as an integrated component within the switching fabric. This nesting enables the system to maintain high detection speed while managing complexity through hierarchical organization of functions.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces a threat aware controller as an intermediary component that coordinates between multiple virtual network switches and their embedded detection engines. This mediator manages the complexity of centralized threat detection across distributed switches, handling threat feed distribution and coordination while allowing local engines to operate independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time monitoring and adaptive threat response are implemented across virtualized network environments, then threat response efficiency is improved, but computational resources and energy consumption increase

Engineering Contradiction:
Improvethreat response efficiencyVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary threat detection and analysis by embedding detection engines within virtual network switches, allowing threats to be identified early in the network traffic flow. This preliminary action enables faster response times while distributing computational load across multiple switches rather than concentrating it in a single analysis point.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The threat detection functionality is segmented and distributed across multiple virtual network switches, with each switch running its own embedded threat detection engine. This segmentation divides the computational burden of real-time monitoring across multiple independent units, reducing the energy consumption and resource demands on any single system component.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12052273B2Virtual switch-based threat defense for networks with multiple virtual network functions
Publication Date: 2024.07.30 CISCO TECHNOLOGY INC
  • US12052273B2 patent drawing
  • US12052273B2 patent drawing
  • US12052273B2 patent drawing

AI summary

Techniques for providing network traffic security in a virtualized environment are described. A threat aware controller uses a threat feed provided by a threat intelligence service to establish a threat detection engine on virtual switches. The threat aware controller and threat detection engine work together to detect any anomalous or malicious behavior of network traffic on the virtual switch and established virtual network functions to quickly detect, verify, and isolate network threats.