Automated Access Control Entity Generation for Network Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for mitigating computer network attacks, such as denial of service (DoS) attacks, rely on manually created access control entities (ACEs) which are time-consuming, prone to being under-inclusive or over-inclusive, and do not effectively utilize existing institutional knowledge, leading to inefficiencies in blocking malicious traffic.
Innovation Solution
An automated system, the ACE Engine, generates recommendations for ACE rules by processing incoming internet packets and examining statistical profiles to produce parameterized ACEs with a quantified confidence score, selecting from a library of pre-authored ACEs using mathematical techniques to determine similarity scores, and deploying them in real-time to block malicious traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual creation of ACE rules is used, then expertise and control are maintained, but time consumption and delays increase
Solution Approach 1:
The system enables automated self-service by allowing the ACE rule generation system to automatically create, optimize, and deploy access control entities without requiring manual intervention from security personnel, thus resolving the contradiction between maintaining accuracy and reducing time delays
Solution Approach 2:
The patent replaces the manual mechanical process of ACE rule creation with an automated computational system that uses machine learning models and statistical analysis to generate optimized rules, eliminating human time constraints while maintaining or improving accuracy through algorithmic precision
2Adaptability or versatility
If manual ACE creation is used, then flexibility in customization is maintained, but under-inclusivity and over-inclusivity occur
Solution Approach 1:
The system implements feedback mechanisms where ACE rules are continuously monitored for their effectiveness, and the system automatically adjusts and optimizes rules based on observed traffic patterns and attack evolution, ensuring both customization flexibility and reliable filtering without under or over-inclusivity
Solution Approach 2:
The patent transforms static manually-created ACE rules into dynamic, adaptive rules that automatically adjust to changing traffic patterns and attack vectors, maintaining versatility while improving reliability through continuous optimization based on real-time data
3Ease of operation
If manual ACE creation is used, then control over rule parameters is maintained, but institutional knowledge is not utilized
Solution Approach 1:
The system performs preliminary actions by pre-processing traffic data, pre-training machine learning models on historical attack patterns, and pre-generating optimized ACE rules based on institutional knowledge before actual attacks occur, thereby improving productivity while maintaining operational control
Solution Approach 2:
The patent segments the ACE rule creation process into distinct automated components including traffic analysis, pattern recognition, rule generation, and validation modules, each handling specific aspects of the process to improve overall efficiency while maintaining controllable parameters through modular design
4Adaptability or versatility
If multiple ACE formats from different manufacturers are supported, then compatibility is improved, but system complexity increases
Solution Approach 1:
The system introduces an intermediary standardized internal format that sits between different manufacturer-specific ACE formats, automatically converting between formats using the intermediary as a bridge, thereby improving compatibility while managing complexity through a unified conversion layer rather than multiple direct translation paths
Data Source
AI summary
The methods and system described herein automatically generate network router access control entities (ACEs) that are used to filter internet traffic and more specifically to block malicious traffic. The rules are generated by an ACE engine that processes incoming internet packets and examines existing ACEs and a statistical profile of the captured packets to produce one or more recommended ACEs with a quantified measure of confidence. Preferably, a recommended ACE is identified in real time of the attack, and preferably selected from a library of pre-authored ACEs. It is then deployed automatically or alternatively sent to system personnel for review and confirmation.


