Zero Hop Ownership Algorithm for Network Threat Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face inefficiencies in detecting and mitigating threats due to reliance on outdated protocols, high overhead in traffic evaluation, and vulnerability to false positives and negatives, particularly in identifying and preventing attacks within the network.
Innovation Solution
A system and method that assigns a responsible interface to monitor communication within a broadcast domain, operating at the data link layer to detect and prevent attacks by passively observing communication and using a zero hop ownership determination algorithm to identify the closest security device interface without querying switches, thus minimizing overhead and avoiding vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewalls and intrusion detection systems are used to protect the network, then security protection is provided, but network overhead increases and false positives/negatives occur
Solution Approach 1:
The patent divides the security monitoring function into distributed security agents deployed on individual network devices rather than centralized firewalls or IDS. Each agent independently monitors its local device, segmenting the security function to reduce centralized overhead and improve reliability through distributed detection.
Solution Approach 2:
Security agents on each device autonomously monitor and detect attacks without requiring centralized control or complex coordination. Each device self-services its own security monitoring, eliminating the overhead of centralized traffic evaluation and reducing false positives through localized context-aware detection.
2Reliability
If centralized intrusion detection systems evaluate all network traffic, then attacks can be detected, but processing time increases and network performance deteriorates
Solution Approach 1:
The patent segments network traffic evaluation to occur locally at distributed security agents rather than centrally. Each agent evaluates only the traffic relevant to its device, dramatically reducing total processing time while maintaining comprehensive attack detection coverage across the network.
Solution Approach 2:
Each security agent performs partial evaluation focused only on its local device's traffic patterns and anomalies, rather than exhaustive evaluation of all network traffic. This partial action approach reduces processing time while maintaining effective attack detection through localized monitoring.
3Reliability
If firewalls filter network traffic based on rules, then unwanted traffic is blocked, but legitimate traffic may be unintentionally blocked and network communication is encumbered
Solution Approach 1:
Security agents autonomously learn normal traffic patterns for each device and dynamically adjust filtering decisions, eliminating the need for static firewall rules that may block legitimate traffic. This self-service approach maintains reliable filtering while preserving network communication by adapting to actual usage patterns.
Solution Approach 2:
The patent replaces static firewall rules with dynamic, adaptive filtering that continuously learns and adjusts to normal traffic patterns. This dynamic approach ensures legitimate traffic flows smoothly while maintaining reliable blocking of unwanted traffic through context-aware detection.
4Measurement precision
If security devices query switches to determine network topology, then responsible interfaces can be identified, but additional overhead and switching device involvement increases
Solution Approach 1:
The patent extracts the network topology discovery function from switching devices and implements it within security agents using passive observation of traffic patterns. This removes the burden from switches while maintaining precise interface identification through analysis of source and destination addresses in observed traffic.
Solution Approach 2:
The patent uses observed network traffic as an intermediary to infer topology relationships without direct queries to switches. By analyzing traffic patterns between devices, security agents indirectly determine responsible interfaces, eliminating the need for switch involvement while maintaining measurement precision.
Data Source
AI summary
A method, system, apparatus, and computer-readable medium to enable a set of security device interfaces within a broadcast domain to identify and mitigate attacks. For each address of a device communicating within the broadcast domain, a responsible interface is determined by a zero hop ownership determination algorithm. The algorithm operates by counting a respective number of replies observed by each of multiple interfaces. Each reply is made in response to a respective request for one address. A responsible interface is assigned to the one address using the respective number of replies observed by each respective interface. The algorithm approximates the security device interface physically closest to the address in question without querying the switches themselves and without requiring the security device interface to be in-line on the network.


