Adaptive Traffic Burst Allocation Beyond Baseline Thresholds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewall systems face challenges in distinguishing between legitimate and malicious traffic during surges, leading to potential denial of service (DoS) attacks, where setting traffic thresholds can inadvertently block genuine traffic, causing disruptions.

Innovation Solution

An adaptive protection system that combines traffic threshold-based protection, a smart burst feature, and attack detection to allow bursts of traffic beyond a baseline threshold while identifying and isolating potential attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traffic threshold is set to protect against DoS attacks, then the system can block malicious traffic, but genuine traffic may be inadvertently blocked causing disruptions

Engineering Contradiction:
Improveprotection against DoS attacksVSAvoidgenuine traffic flow
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic threshold adjustment by continuously monitoring traffic patterns and automatically adapting the threshold values. The system transitions from static threshold configuration to dynamic threshold management, allowing the firewall to respond to changing traffic conditions in real-time. This resolves the contradiction by enabling the system to maintain high protection levels during attacks while automatically permitting genuine traffic surges when patterns indicate legitimacy.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters simultaneously including threshold values, monitoring time windows, and traffic classification criteria. By adjusting these parameters dynamically based on observed traffic patterns, the system can differentiate between malicious and genuine traffic surges. This multi-parameter approach allows the firewall to maintain reliability against attacks while preserving productivity for legitimate traffic.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traffic thresholds are set low to ensure security, then attack traffic is blocked, but system functionality is reduced due to blocked legitimate traffic

Engineering Contradiction:
Improvesecurity threshold enforcementVSAvoidsystem functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously monitors traffic patterns, evaluates the effectiveness of threshold enforcement, and adjusts thresholds accordingly. The feedback loop includes analyzing blocked traffic, identifying false positives, and refining threshold parameters. This resolves the contradiction by enabling the system to maintain security while learning from operational data to reduce unnecessary blocking of legitimate traffic.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The firewall system performs self-adjustment of thresholds without requiring manual intervention. The system automatically monitors its own performance, identifies patterns indicating genuine traffic, and modifies its threshold enforcement behavior accordingly. This self-service capability maintains security while preserving system functionality by autonomously resolving false positives.

Inventive Principle:
Principle #25Self-service

3Reliability

If the firewall system processes all incoming traffic flows, then security monitoring is comprehensive, but flow capacity is depleted during attack traffic

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidflow capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments traffic processing into different categories and applies different handling strategies to each segment. High-priority traffic receives full inspection while low-priority or suspicious traffic receives simplified processing or rate limiting. This segmentation allows the system to maintain comprehensive security monitoring for critical traffic while conserving flow capacity during attacks by reducing processing overhead for non-critical traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial processing to certain traffic flows based on their characteristics and priority levels. Instead of uniformly processing all traffic at full depth, the firewall applies selective processing intensity. This partial action approach maintains security monitoring coverage for important traffic while reducing the overall processing burden and preserving flow capacity during attack conditions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250286830A1Traffic burst capacity allocation
Publication Date: 2025.09.11 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250286830A1 patent drawing
  • US20250286830A1 patent drawing
  • US20250286830A1 patent drawing

AI summary

In some examples, a protection system determines, based on monitoring a traffic volume in a computing environment, a baseline traffic threshold for the computing environment. The protection system allocates, based on a capacity of the protection system and the baseline traffic threshold, a burst threshold to the computing environment for adding a traffic burst capacity. The protection system determines a traffic integrity of data traffic in the computing environment based on a property of the data traffic. Based on the determined traffic integrity in the computing environment, the protection system allows additional traffic in the computing environment beyond the baseline traffic threshold up to the burst threshold.