Dynamic Filter Generation for Network Traffic Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer networks face significant security risks due to malicious activities, and existing filtering technologies are inadequate in efficiently identifying and mitigating malicious network traffic, as they often rely on individual checks of IP addresses rather than common patterns, leading to inefficiencies and potential false positives.
Innovation Solution
A filter management system generates filters based on common network traffic attributes found in blocklist data, grouping entries to create comprehensive filter rules that can be deployed across network devices, utilizing both hardware and software filtering mechanisms to identify and block malicious traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual IP address filtering is used, then specific malicious traffic can be blocked, but the number of false positives increases and processing efficiency decreases
Solution Approach 1:
The patent combines multiple individual IP address filters into a single consolidated filter structure. Instead of processing each IP address separately through individual filtering rules, the system merges them into a unified filter that handles multiple addresses simultaneously, reducing the total number of filtering operations and improving processing efficiency while maintaining accurate identification of malicious traffic.
Solution Approach 2:
The patent creates a universal filter structure that can handle multiple IP addresses and traffic patterns through a single filtering mechanism. This multi-functional filter replaces numerous specialized individual filters, allowing the system to process diverse malicious traffic types efficiently while reducing false positives through standardized evaluation criteria.
2Reliability
If comprehensive individual filtering rules are created for each malicious entry, then identification accuracy improves, but filter complexity and deployment overhead increase
Solution Approach 1:
The patent merges multiple complex individual filtering rules into a single consolidated filter structure. By combining the logic of numerous individual rules into one unified filter, the system maintains comprehensive coverage of malicious traffic patterns while significantly reducing the complexity of filter deployment and management across network devices.
Solution Approach 2:
The patent segments the filter into hierarchical levels, with a consolidated high-level structure that organizes multiple IP addresses and traffic patterns into manageable groups. This segmentation allows the filter to maintain detailed identification capabilities for each malicious entry while presenting a simplified overall structure that is easier to deploy and manage across the network.
3Ease of manufacture
If static filtering rules are used, then filter deployment is simple, but adaptability to new threats decreases
Solution Approach 1:
The patent implements dynamic filter generation that automatically updates the consolidated filter structure based on newly identified malicious IP addresses and traffic patterns. The system transitions from static, manually-configured filters to dynamic filters that adapt in real-time to emerging threats, maintaining both deployment simplicity through automation and high adaptability to new malicious activities.
Solution Approach 2:
The patent incorporates feedback mechanisms where the filtering system continuously monitors network traffic, identifies new malicious patterns, and automatically updates the consolidated filter rules. This feedback loop ensures the filter remains adaptive to new threats while maintaining simple deployment through automated update propagation across the network infrastructure.
Data Source
AI summary
Systems and methods for implementing filters within computer networks include obtaining blocklist data that includes blocklist entries for a network. Each of the blocklist entries includes one or more network traffic attributes for identifying traffic to be blocked. In response to receiving the blocklist data, a filter based on a common network traffic attribute shared between at least two of the plurality of blocklist entries is generated. The filter is then deployed to a network device within the network such that the filter may be implemented at the network device to block corresponding traffic.


