Connectivity Protector Buffering Client Traffic to Prevent False DOS Blocks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing client-side solutions for preventing Denial of Service (DOS) attacks often result in erroneous disconnections due to improper traffic detection, leading to significant user experience issues and support costs, as users cannot tune or disable these measures.
Innovation Solution
An apparatus and method that include an outbound buffer and connection monitor to buffer client communications, preventing flood block responses and protecting connectivity by analyzing and modifying traffic characteristics to avoid misidentification as malicious.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If client-side blocking is implemented to prevent DOS attacks, then server protection is improved, but user experience deteriorates due to erroneous disconnections
Solution Approach 1:
The patent introduces a mediator component that sits between the flood blocker and the client connection, analyzing traffic patterns to distinguish between legitimate high-volume traffic and actual DOS attacks. This intermediary layer prevents erroneous blocking by providing additional verification before disconnection occurs.
Solution Approach 2:
The system dynamically adjusts blocking parameters such as threshold values and time windows based on observed traffic patterns and historical data. This allows the system to adapt to legitimate high-volume traffic scenarios while maintaining protection against actual DOS attacks, reducing false positives.
2Reliability
If flood blocking is enabled to detect malicious traffic, then DOS attack prevention is improved, but traffic detection accuracy deteriorates leading to false positives
Solution Approach 1:
The system implements feedback loops where blocking decisions are continuously refined based on outcomes. When legitimate traffic is erroneously blocked, the system learns from this feedback and adjusts its detection algorithms to avoid similar false positives in the future, improving detection accuracy over time.
Solution Approach 2:
The patent employs preliminary analysis of traffic patterns, connection behaviors, and user profiles before making blocking decisions. By performing preliminary verification and establishing baseline behavior patterns, the system can more accurately distinguish between legitimate and malicious traffic, reducing false positives.
3Reliability
If automatic blocking is implemented without user control, then DOS protection is improved, but user autonomy deteriorates
Solution Approach 1:
The system transitions from static, fixed blocking rules to dynamic, adaptive blocking behavior that responds to real-time conditions and user needs. Users can adjust blocking sensitivity, time windows, and threshold values, allowing the system to adapt to different use cases and user preferences while maintaining protection.
Solution Approach 2:
The patent implements self-service capabilities where users can review blocked connections, adjust their own blocking preferences, and configure exceptions for specific applications or time periods. This empowers users to manage their own connectivity while maintaining DOS protection.
Data Source
AI summary
A method of protecting connectivity in a network is provided. The method includes monitoring a client communication received from a client on the network, and determining, based on the monitoring, to buffer the client communication. Next, to avoid a flood block response from a node on the network, based on the determining the client communication is buffered, whereby the connectivity of the client is protected.


