White Box Infection Detection via Processing Time Anomaly

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software-defined networks (SDNs) utilizing white box hardware, the identical or similar design of commodity equipment makes it vulnerable to widespread network disruptions and data theft, as a compromised white box can lead to infiltration across the network, causing outages and illicit activities.

Innovation Solution

A white box integrity management system (WIMS) is implemented to monitor and challenge each white box, determining processing times for responses to identify compromised units and isolate them from the network if the time exceeds a predetermined percentage of the average, thereby preventing further damage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If white box hardware is used to reduce costs and provide flexibility, then device complexity and cost are reduced, but vulnerability to widespread network disruption increases

Engineering Contradiction:
Improvehardware complexityVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary integrity verification by sending challenges to white box hardware before they can be exploited. Processing time measurements are taken in advance to establish baseline performance characteristics, enabling early detection of compromised devices before they can cause widespread network disruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors processing time responses from white box hardware and compares them against expected ranges. When anomalies are detected, the system provides feedback by isolating the compromised device from the network, preventing further propagation of security threats while maintaining overall network integrity.

Inventive Principle:
Principle #23Feedback

2Ease of manufacture

If identical or similar white box equipment is deployed throughout the network, then ease of manufacture and deployment is improved, but susceptibility to hacker exploitation increases

Engineering Contradiction:
Improvedeployment easeVSAvoidhacker exploitation risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system applies localized integrity verification to each individual white box device through unique challenge-response mechanisms. Each device is independently monitored for processing time anomalies, allowing the system to identify and isolate compromised devices without affecting the operation of other identical devices in the network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system monitors changes in processing time parameters as an indicator of device compromise. By establishing baseline performance characteristics for identical white box hardware and detecting deviations from these baselines, the system can identify infected devices while allowing uniform deployment of standardized hardware throughout the network.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If processing time monitoring is used to detect compromised white boxes, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveinfection detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The white box hardware devices perform self-verification by responding to challenges sent by the network controller. Each device calculates its own processing time and returns the result, allowing the system to detect compromises through automated measurement without requiring complex external verification infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces complex physical security verification mechanisms with computational processing time measurements. By using software-based challenge-response protocols and timing analysis, the system achieves accurate infection detection without requiring complex hardware security modules or manual verification procedures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11316884B2Software defined network white box infection detection and isolation
Publication Date: 2022.04.26 AT&T INTELLECTUAL PROPERTY I L P
  • US11316884B2 patent drawing
  • US11316884B2 patent drawing
  • US11316884B2 patent drawing

AI summary

A method and system for white box infection detection and isolation. The methods and systems can monitor a plurality of white boxes deployed within a communications network; send a challenge to a first white box of the plurality of white boxes; determine a processing time to answer the challenge by the first white box; in response to receiving the answer to the challenge, determine whether the processing time exceeds an average processing time for the challenge by a predetermined percentage; and in response to the processing time exceeding the average processing time by the predetermined percentage, isolate the first white box from the communications network.