Automated Access Control Entity Generation for Network Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for mitigating computer network attacks, such as denial of service (DoS) attacks, rely on manually created access control entities (ACEs) which are time-consuming, prone to being under-inclusive or over-inclusive, and do not effectively utilize existing institutional knowledge, leading to inefficiencies in blocking malicious traffic.

Innovation Solution

An automated system, the ACE Engine, generates recommendations for ACE rules by processing incoming internet packets and examining statistical profiles to produce parameterized ACEs with a quantified confidence score, selecting from a library of pre-authored ACEs using mathematical techniques to determine similarity scores, and deploying them in real-time to block malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual creation of ACE rules is used, then expertise and control are maintained, but time consumption and delays increase

Engineering Contradiction:
Improveaccuracy of ACE rule creationVSAvoidtime delay in ACE rule deployment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automated self-service by allowing the ACE rule generation system to automatically create, optimize, and deploy access control entities without requiring manual intervention from security personnel, thus resolving the contradiction between maintaining accuracy and reducing time delays

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of ACE rule creation with an automated computational system that uses machine learning models and statistical analysis to generate optimized rules, eliminating human time constraints while maintaining or improving accuracy through algorithmic precision

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If manual ACE creation is used, then flexibility in customization is maintained, but under-inclusivity and over-inclusivity occur

Engineering Contradiction:
Improvecustomization flexibilityVSAvoideffectiveness of traffic filtering
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where ACE rules are continuously monitored for their effectiveness, and the system automatically adjusts and optimizes rules based on observed traffic patterns and attack evolution, ensuring both customization flexibility and reliable filtering without under or over-inclusivity

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent transforms static manually-created ACE rules into dynamic, adaptive rules that automatically adjust to changing traffic patterns and attack vectors, maintaining versatility while improving reliability through continuous optimization based on real-time data

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If manual ACE creation is used, then control over rule parameters is maintained, but institutional knowledge is not utilized

Engineering Contradiction:
Improvecontrol over ACE parametersVSAvoidefficiency of attack mitigation
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-processing traffic data, pre-training machine learning models on historical attack patterns, and pre-generating optimized ACE rules based on institutional knowledge before actual attacks occur, thereby improving productivity while maintaining operational control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the ACE rule creation process into distinct automated components including traffic analysis, pattern recognition, rule generation, and validation modules, each handling specific aspects of the process to improve overall efficiency while maintaining controllable parameters through modular design

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If multiple ACE formats from different manufacturers are supported, then compatibility is improved, but system complexity increases

Engineering Contradiction:
Improvecompatibility with device typesVSAvoidcomplexity of ACE format conversion
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary standardized internal format that sits between different manufacturer-specific ACE formats, automatically converting between formats using the intermediary as a bridge, thereby improving compatibility while managing complexity through a unified conversion layer rather than multiple direct translation paths

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11895145B2Systems and methods for automatically selecting an access control entity to mitigate attack traffic
Publication Date: 2024.02.06 AKAMAI TECHNOLOGIES INC
  • US11895145B2 patent drawing
  • US11895145B2 patent drawing
  • US11895145B2 patent drawing

AI summary

The methods and system described herein automatically generate network router access control entities (ACEs) that are used to filter internet traffic and more specifically to block malicious traffic. The rules are generated by an ACE engine that processes incoming internet packets and examines existing ACEs and a statistical profile of the captured packets to produce one or more recommended ACEs with a quantified measure of confidence. Preferably, a recommended ACE is identified in real time of the attack, and preferably selected from a library of pre-authored ACEs. It is then deployed automatically or alternatively sent to system personnel for review and confirmation.