Edge Cleansing Farm for Cyber Attack Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern Internet networks face prevalent and damaging cyber attacks, particularly denial of service attacks, which existing mitigation strategies struggle to adaptively address, especially when confidential information is involved, requiring a robust and adaptable filtering solution.

Innovation Solution

Implementing an Internet edge cleansing farm that filters customer requests using computing devices to apply filtering rules across various layers of the OSI communication model, including deep packet inspection, and visualizes request data to generate and apply rules, thereby mitigating denial of service attacks and protecting confidential information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing mitigation tactics are used to deter cyber attackers, then some protection is provided, but confidential information remains vulnerable and the strategy lacks adaptability against agile attackers

Engineering Contradiction:
Improveprotection against cyber attacksVSAvoidadaptability of mitigation strategy
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its filtering rules based on real-time analysis of customer requests and attack patterns. The cleansing farm continuously updates its mitigation strategies by learning from incoming traffic patterns, making the defense mechanism flexible and responsive to evolving cyber threats rather than relying on static rules

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where the visualization tool and analysis mechanisms monitor incoming requests, identify attack patterns, and automatically adjust filtering rules. This closed-loop approach allows the mitigation strategy to continuously improve based on observed attacker behavior and system performance

Inventive Principle:
Principle #23Feedback

2Measurement precision

If packet inspection is performed across all layers of the OSI model including deep packet inspection, then filtering accuracy is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvefiltering accuracyVSAvoidrequest processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs deep packet inspection selectively rather than uniformly on all requests. The visualization tool and analysis mechanisms identify requests that require intensive multi-layer inspection versus those that can be handled by simpler filtering rules, applying excessive inspection only where necessary to maintain accuracy while reducing overall processing time

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The packet inspection process is segmented into multiple stages corresponding to different OSI layers. The system performs preliminary filtering at lower layers and reserves deep inspection for specific layers only when lower-layer filtering identifies suspicious patterns, dividing the inspection task into manageable segments that reduce overall processing time

Inventive Principle:
Principle #1Segmentation

3Reliability

If a cleansing farm filters all customer requests before routing internally, then security is improved, but the system complexity and infrastructure requirements increase

Engineering Contradiction:
Improvesecurity of customer requestsVSAvoidcomplexity of filtering system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cleansing farm acts as an intermediary layer between external customers and the internal organization network. This mediator performs filtering and security checks, allowing the internal system to remain relatively simple while handling only validated requests. The intermediary absorbs the complexity of security operations externally

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cleansing farm is designed to perform multiple functions including filtering, packet inspection, visualization, rule generation, and request routing through a single integrated system. This multi-functionality reduces overall system complexity by consolidating what could be separate specialized components into one universal security infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9160711B1Internet cleaning and edge delivery
Publication Date: 2015.10.13 BANK OF AMERICA CORP
  • US9160711B1 patent drawing
  • US9160711B1 patent drawing
  • US9160711B1 patent drawing

AI summary

Methods, systems, and computer-readable media for implementing a cleansing farm are presented. A cleansing farm may comprise of a computing device that filters customer requests directed to an organization before they are routed internal to the organization. A cleansing farm may receive customer requests and filter the requests based on a set of filtering rules. The cleansing farm may inspect the customer request in order to determine whether it should be filtered. In an example where the organization is a financial institution, the customer request may include confidential customer information. Accordingly, in this example, the cleansing farm may be administered by an entity that is permitted to access the confidential customer information. A visualization tool may be used to visualize a plurality of customer requests at a cleansing farm and to generate rules for filtering customer requests at a cleansing farm.