Intrusion Prevention System Byte-Level Traffic Alteration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security solutions, such as IDS and IPS, inefficiently handle intrusion events by blocking packets or terminating connections, leading to wasteful use of network resources and unintended disruption of legitimate data traffic.

Innovation Solution

An Intrusion Prevention System (IPS) monitors network data traffic at the byte level, altering or injecting new bytes to neutralize intrusion events while allowing harmless traffic to pass through, thereby preventing successful attacks without consuming network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional IPS blocks packets or terminates connections to prevent intrusion events, then security protection is improved, but network resource efficiency deteriorates due to wasted bandwidth and unnecessary retransmissions

Engineering Contradiction:
Improveintrusion prevention effectivenessVSAvoidnetwork resource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the harmful portion of network data traffic (the intrusion event) and removes it through byte-level alteration or injection, while allowing the rest of the legitimate traffic to continue flowing. This selective removal approach prevents the need to block entire packets or terminate connections, thereby maintaining security protection while avoiding waste of network resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by performing byte-level alterations or injections at specific positions within the data stream where intrusion events occur. Instead of applying a global block or connection termination, the system modifies only the local problematic bytes while leaving the rest of the traffic unchanged, thus preventing intrusion without wasting network resources on legitimate data.

Inventive Principle:
Principle #3Local quality

2Reliability

If conventional IPS blocks intrusion packets, then security protection is improved, but productivity deteriorates due to TCP retransmission cycles consuming time and bandwidth

Engineering Contradiction:
Improveintrusion prevention effectivenessVSAvoidnetwork throughput efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary action by detecting and altering intrusion bytes before they can complete the harmful transmission. By injecting corrective bytes or modifying malicious bytes in advance, the system prevents the intrusion event from reaching its destination while avoiding the need for TCP retransmission cycles, thus maintaining both security and productivity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If conventional IPS terminates TCP connections to stop intrusion events, then security protection is improved, but ease of operation deteriorates due to disruption of legitimate data delivery

Engineering Contradiction:
Improveintrusion prevention effectivenessVSAvoidlegitimate traffic delivery
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts and removes only the harmful intrusion bytes from the data stream through byte-level alteration or injection, while preserving the legitimate portions of the traffic. This selective extraction allows legitimate data delivery to continue uninterrupted, avoiding the need to terminate entire TCP connections and thus maintaining ease of operation for valid communications.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by modifying only the specific bytes containing intrusion events while leaving the rest of the data stream unchanged. This localized modification approach ensures that legitimate traffic maintains its original integrity and can be delivered successfully, avoiding the broad disruption caused by connection termination.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7657938B2Method and system for protecting computer networks by altering unwanted network data traffic
Publication Date: 2010.02.02 KYNDRYL INC
  • US7657938B2 patent drawing
  • US7657938B2 patent drawing
  • US7657938B2 patent drawing

AI summary

Protecting computer networks by altering unwanted network data traffic. An Intrusion Protection System (IPS) or an Intrusion Detection System (IDS) can monitor network data traffic comprising byte information. This network security device analyzes network data traffic at the byte level to determine whether an intrusion event is present in the network data traffic. If an intrusion event is detected, the network security device alters at least a portion of the relevant byte information to prevent the occurrence of a successful intrusion event at the intended destination. This altered byte information is then passed to the destination by the network security device. If an intrusion event is not present, the network security device passes the byte information without alteration to the destination.