IP Reputation System for Network Threat Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in protecting their computer networks from diverse and evolving internet threats, including botnets, malware, and phishing attacks, as existing systems struggle to effectively identify and block malicious IP addresses in real-time.

Innovation Solution

A system comprising a processor and log collection circuits that aggregate real-time IP reputation information from multiple intelligence sources to generate and transmit threat data, enabling firewalls to filter both inbound and outbound traffic from known malicious IP addresses, thereby proactively guarding networks against threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If real-time IP reputation information is aggregated from multiple intelligence sources, then the accuracy of threat identification is improved, but the system complexity and data processing requirements increase

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system divides the complex task of IP reputation assessment into separate functional modules: log collection circuits that gather data from multiple intelligence sources, a central processor that analyzes the aggregated data, and firewall integration components that enforce blocking decisions. This segmentation allows each component to specialize in specific tasks, improving overall accuracy while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces log collection circuits as intermediary components between multiple intelligence sources and the central processing system. These circuits aggregate data from diverse sources (spam reports, malware databases, botnet tracking systems) and present unified reputation information to the processor, simplifying the integration of multiple data streams while maintaining high identification accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If continuous monitoring and updating of IP reputation information is implemented, then the reliability of network protection is improved, but the energy consumption and processing load increase

Engineering Contradiction:
Improvenetwork protection reliabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements periodic updates of IP reputation information at scheduled intervals rather than continuous real-time monitoring. Log collection circuits periodically query intelligence sources and update the reputation database, reducing energy consumption and processing load while maintaining reliable protection by ensuring threat intelligence is current enough to block active threats effectively.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system employs automated processes where log collection circuits autonomously gather data from intelligence sources, the processor automatically analyzes reputation information and identifies threatening IPs, and firewalls self-adjust their blocking rules without manual intervention. This self-service automation maintains high reliability through continuous operation while optimizing resource usage by performing tasks only when needed.

Inventive Principle:
Principle #25Self-service

3Reliability

If both inbound and outbound traffic are filtered based on IP reputation, then the comprehensive security coverage is improved, but the device complexity and processing requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidfiltering system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal IP reputation filtering system that handles both inbound and outbound traffic through the same core mechanism. The log collection circuits gather reputation data, the processor generates blocking rules, and firewalls apply these rules bidirectionally to both incoming and outgoing connections. This multi-functional approach provides comprehensive security coverage while avoiding the need for separate filtering systems for each traffic direction, thereby managing complexity efficiently.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9319382B2System, apparatus, and method for protecting a network using internet protocol reputation information
Publication Date: 2016.04.19 CAUTELA LABS
  • US9319382B2 patent drawing
  • US9319382B2 patent drawing
  • US9319382B2 patent drawing

AI summary

Certain embodiments described herein provide a computer system, a log collection device, and methods for protecting a plurality of guarded networks from internet threats. The computer system includes at least one processor in operative communication with a plurality of log collection circuits via the internet and in operative communication with a plurality of intelligence sources via the internet. The log collection circuit includes at least one processor in operative communication with a computer system via the internet and in operative communication with at least one firewall of the guarded network. The at least one processor of the computer system is operative to receive traffic information from each log collection circuit of the plurality of log collection circuits, to receive intelligence data from the plurality of intelligence sources, to generate reputation information regarding one or more addresses of the plurality of addresses, and to transmit the reputation information to each log collection circuit of the plurality of log collection circuits.