Dynamic Network Traffic Filtering for DoS Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices are often unable to protect against high-rate malicious attacks, such as Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, which can overwhelm processing resources and render service components inoperable, leading to network instability and the need for administrative intervention.

Innovation Solution

A network device equipped with dynamic firewall filters that adjust based on the rate of incoming traffic and processor usage, allowing it to filter out packets from suspicious subscribers, thereby conserving resources and maintaining network integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network device filters packets dynamically based on traffic rate and processor usage, then the network device can protect against DoS/DDoS attacks and maintain service availability, but the device complexity increases due to dynamic filter management

Engineering Contradiction:
Improveservice availabilityVSAvoidfilter management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic firewall filter management where filters are automatically installed, modified, and removed based on real-time traffic rate thresholds and processor usage conditions. The system transitions from static to dynamic filter deployment, allowing the network device to adapt its security posture automatically without manual intervention during attack conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors traffic rates and processor usage, comparing them against predefined thresholds to determine when to install or remove filtering actions. This feedback mechanism creates a closed-loop system that automatically responds to attack conditions, adjusting filter behavior based on real-time network state without requiring continuous administrative input.

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If the network device implements dynamic filtering based on traffic rate thresholds, then malicious traffic can be blocked while legitimate traffic is permitted, but false positives may occur causing legitimate traffic to be blocked

Engineering Contradiction:
Improvemalicious traffic blockingVSAvoidlegitimate traffic delivery
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system uses adjustable traffic rate thresholds and processor usage conditions as parameters that can be configured to balance security sensitivity with legitimate traffic preservation. By tuning these parameters, administrators can optimize the system to block malicious traffic while minimizing false positives that would inadvertently block legitimate communications.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies filtering selectively based on detected attack conditions rather than implementing blanket blocking. Filters are deployed only when traffic rates exceed thresholds or processor usage indicates attack conditions, allowing legitimate traffic to pass during normal operation while providing aggressive filtering only when necessary to counter actual threats.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If the network device continuously monitors traffic rates and processor usage for filter management, then dynamic filtering can be optimized, but the processor usage increases consuming network resources

Engineering Contradiction:
Improvefilter optimizationVSAvoidprocessor usage
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The network device performs self-monitoring and self-adjustment by continuously tracking its own traffic rates and processor usage to automatically manage firewall filter deployment. This self-service capability eliminates the need for external monitoring systems or manual configuration adjustments, allowing the device to optimize its security posture using its own operational data without requiring additional administrative resources.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback from its own operational metrics (traffic rate monitoring and processor usage tracking) to automatically adjust filter behavior. This internal feedback loop allows the device to optimize filtering based on real-time conditions without requiring external intervention, balancing security effectiveness with resource consumption by using the device's own performance data to guide its security actions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10382340B1Dynamic filtering of network traffic
Publication Date: 2019.08.13 JUNIPER NETWORKS INC
  • US10382340B1 patent drawing
  • US10382340B1 patent drawing
  • US10382340B1 patent drawing

AI summary

A device may include one or more memories, and one or more processors to receive a plurality of packets over a network. Packets, of the plurality of packets, may relate to a subscriber. The subscriber may be a source subscriber from which the packets are initiated or a destination subscriber to which the packets are destined. The device may determine whether a rate of receipt of the packets satisfies a first threshold, detect whether a level of processor usage satisfies a second threshold, and perform one or more actions to cause filtering of additional packets relating to the subscriber based on whether the rate of receipt of the packets satisfies the first threshold and based on whether the level of processor usage satisfies the second threshold. The device may monitor filtering of the additional packets to determine whether to filter further packets relating to the subscriber.