Dynamic Filter Generation for Network Traffic Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks face significant security risks due to malicious activities, and existing filtering technologies are inadequate in efficiently identifying and mitigating malicious network traffic, as they often rely on individual checks of IP addresses rather than common patterns, leading to inefficiencies and potential false positives.

Innovation Solution

A filter management system generates filters based on common network traffic attributes found in blocklist data, grouping entries to create comprehensive filter rules that can be deployed across network devices, utilizing both hardware and software filtering mechanisms to identify and block malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual IP address filtering is used, then specific malicious traffic can be blocked, but the number of false positives increases and processing efficiency decreases

Engineering Contradiction:
Improveaccuracy of malicious traffic identificationVSAvoidprocessing efficiency of network traffic
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple individual IP address filters into a single consolidated filter structure. Instead of processing each IP address separately through individual filtering rules, the system merges them into a unified filter that handles multiple addresses simultaneously, reducing the total number of filtering operations and improving processing efficiency while maintaining accurate identification of malicious traffic.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal filter structure that can handle multiple IP addresses and traffic patterns through a single filtering mechanism. This multi-functional filter replaces numerous specialized individual filters, allowing the system to process diverse malicious traffic types efficiently while reducing false positives through standardized evaluation criteria.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive individual filtering rules are created for each malicious entry, then identification accuracy improves, but filter complexity and deployment overhead increase

Engineering Contradiction:
Improvemalicious traffic identification accuracyVSAvoidfilter structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple complex individual filtering rules into a single consolidated filter structure. By combining the logic of numerous individual rules into one unified filter, the system maintains comprehensive coverage of malicious traffic patterns while significantly reducing the complexity of filter deployment and management across network devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the filter into hierarchical levels, with a consolidated high-level structure that organizes multiple IP addresses and traffic patterns into manageable groups. This segmentation allows the filter to maintain detailed identification capabilities for each malicious entry while presenting a simplified overall structure that is easier to deploy and manage across the network.

Inventive Principle:
Principle #1Segmentation

3Ease of manufacture

If static filtering rules are used, then filter deployment is simple, but adaptability to new threats decreases

Engineering Contradiction:
Improvefilter deployment simplicityVSAvoidadaptability to new malicious threats
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic filter generation that automatically updates the consolidated filter structure based on newly identified malicious IP addresses and traffic patterns. The system transitions from static, manually-configured filters to dynamic filters that adapt in real-time to emerging threats, maintaining both deployment simplicity through automation and high adaptability to new malicious activities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where the filtering system continuously monitors network traffic, identifies new malicious patterns, and automatically updates the consolidated filter rules. This feedback loop ensures the filter remains adaptive to new threats while maintaining simple deployment through automated update propagation across the network infrastructure.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240340268A1Dynamic filter generation and distribution within computer networks
Publication Date: 2024.10.10 LEVEL 3 COMMUNICATIONS LLC
  • US20240340268A1 patent drawing
  • US20240340268A1 patent drawing
  • US20240340268A1 patent drawing

AI summary

Systems and methods for implementing filters within computer networks include obtaining blocklist data that includes blocklist entries for a network. Each of the blocklist entries includes one or more network traffic attributes for identifying traffic to be blocked. In response to receiving the blocklist data, a filter based on a common network traffic attribute shared between at least two of the plurality of blocklist entries is generated. The filter is then deployed to a network device within the network such that the filter may be implemented at the network device to block corresponding traffic.