Kernel-Level Network Traffic Filtering and Session Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network communication systems face challenges in monitoring and managing traffic from various applications, particularly messenger applications that increase network loads and can lead to malicious data theft, as they struggle to detect and control unnecessary and malicious traffic effectively.
Innovation Solution
A system comprising a network traffic managing device and a traffic control device that creates and transmits monitoring and filtering policies to user terminals, allowing for packet detection, classification, and filtering at the kernel level, thereby managing network traffic and blocking malicious communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If messenger applications periodically transmit session maintenance data to servers, then session continuity is maintained, but network load increases significantly
Solution Approach 1:
The system performs preliminary classification of packets into monitored and non-monitored categories before actual transmission. By pre-identifying session maintenance packets and marking them for special handling, the system can aggregate and batch transmit these packets rather than sending them individually, thereby reducing overall network load while maintaining session continuity.
2Adaptability or versatility
If all applications transmit data independently to maintain sessions, then application functionality is preserved, but network system load increases
Solution Approach 1:
The patent merges multiple independent application traffic streams into a unified monitored traffic flow. By consolidating session maintenance packets from multiple applications through a single monitoring point and applying aggregate filtering policies, the system reduces redundant transmissions and lowers overall network load while preserving individual application functionalities.
3Reliability
If network traffic monitoring is implemented to detect malicious data, then data security is improved, but system complexity increases
Solution Approach 1:
The monitoring system is segmented into distinct functional modules: packet collection unit, packet monitoring unit, traffic managing unit, and packet filtering unit. Each module performs a specific function in the traffic analysis chain, allowing for independent optimization and maintenance while collectively providing comprehensive security monitoring without overwhelming system complexity.
Solution Approach 2:
The patent introduces a traffic managing unit as an intermediary between the packet monitoring unit and packet filtering unit. This intermediary component analyzes traffic patterns, makes intelligent decisions about which packets to allow or block, and coordinates the actions of other modules, thereby simplifying the overall system architecture while maintaining effective security monitoring.
4Productivity
If packet filtering is performed at kernel area, then traffic control efficiency is improved, but processing overhead increases
Solution Approach 1:
The system applies partial filtering by focusing monitoring and filtering resources only on specific packet types that require security attention, such as session maintenance packets and potentially malicious traffic. By not filtering every packet equally but instead applying selective filtering based on predefined policies, the system achieves effective traffic control while minimizing unnecessary processing overhead.
Data Source
AI summary
Disclosed herein are a system for managing network traffic by using monitoring and filtering policies, including: a network traffic managing device to manage network traffic by (i) creating a monitoring policy and a filtering policy and (ii) transmitting the created monitoring policy and the created filtering policy to a user terminal device; and a traffic control device to detect packets generated in one or more applications of the user terminal device, according to the one or more applications or one or more destination addresses based on the monitoring policy received from the network traffic managing device, create and transmit traffic statistical information on the detected packets to the network traffic managing device, and filter the packets according to the filtering policy received from the network traffic managing device at a kernel area of the user terminal device.


