Dynamic Gateway Rules for Critical Traffic Availability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Internet and its applications are vulnerable to cyber attacks and overloading, which can disrupt critical communications infrastructure, and existing technologies fail to ensure availability and restore functionality during such events.

Innovation Solution

Deploying packet security gateways at network boundaries to enforce dynamic filtering policies that prioritize critical communications, allowing essential traffic while blocking or rate-limiting non-essential traffic, and progressively expanding access as overload conditions are mitigated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packet filtering rules are applied to block malicious traffic during cyber attacks, then network security is improved, but legitimate traffic may also be blocked causing service disruption

Engineering Contradiction:
Improvenetwork securityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic packet filtering where the set of filtering rules is not static but can be modified in response to detected attack patterns. The system dynamically adjusts which packets to block based on real-time analysis of traffic patterns, allowing it to distinguish between malicious and legitimate traffic more effectively, thus maintaining service availability while improving security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs feedback mechanisms where the effects of packet filtering are monitored and used to adjust subsequent filtering decisions. By observing whether blocked packets were actually malicious or legitimate, the system refines its filtering rules to reduce false positives while maintaining security, resolving the contradiction between security and service availability.

Inventive Principle:
Principle #23Feedback

2Reliability

If packet security gateways are deployed at network boundaries to filter traffic, then protection from cyber attacks is improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improveprotection from cyber attacksVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the packet security gateway functionality into modular components that can be independently deployed and managed. Rather than a monolithic complex system, the filtering capabilities are divided into separate rule sets and enforcement points, making the overall system easier to implement, maintain, and update while providing comprehensive protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The packet security gateway is designed to perform multiple functions including traffic filtering, attack detection, and dynamic rule adjustment within a single system. This multi-functionality reduces the need for multiple separate security devices and simplifies implementation while maintaining robust protection against various types of cyber attacks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dynamic filtering policies are enforced to prioritize critical communications during overload, then availability for essential users is improved, but network traffic management complexity increases

Engineering Contradiction:
Improveavailability for essential usersVSAvoidtraffic management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies different filtering policies to different types of traffic based on their criticality. Rather than uniform filtering, the system identifies and applies specialized rules for critical communications versus standard traffic, allowing essential users to maintain availability while managing overall network load. This localized approach to traffic management simplifies the complexity by focusing detailed policy enforcement only where necessary.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12452270B2Protecting networks from cyber attacks and overloading
Publication Date: 2025.10.21 CENTRIPETAL NETWORKS INC
  • US12452270B2 patent drawing
  • US12452270B2 patent drawing
  • US12452270B2 patent drawing

AI summary

Packets may be received by a packet security gateway. Responsive to a determination that an overload condition has occurred in one or more networks associated with the packet security gateway, a first group of packet filtering rules may be applied to at least some of the packets. Applying the first group of packet filtering rules may include allowing at least a first portion of the packets to continue toward their respective destinations. Responsive to a determination that the overload condition has been mitigated, a second group of packet filtering rules may be applied to at least some of the packets. Applying the second group of packet filtering rules may include allowing at least a second portion of the packets to continue toward their respective destinations.