Midserver Traffic Aggregation for Mass Scan Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large business enterprises face challenges in managing data collection, security, and network traffic analysis due to heterogeneous data transfer, lack of reliable data collection methods, poor protocol support, security concerns, and inefficient bandwidth usage, especially when using cloud-based services, leading to unorganized data management and increased security risks.

Innovation Solution

A midserver-based system is introduced to detect and analyze network traffic, equipped with sensors and containerized services to collect, aggregate, analyze, and securely transmit data, reducing network connections and enhancing security by identifying threats like botnets and malicious connections using heuristic and signature-based techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If each computing device sends data to cloud-based service on separate connections, then data collection coverage is improved, but network security risks increase and bandwidth efficiency deteriorates

Engineering Contradiction:
Improvedata collection coverageVSAvoidnetwork security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent introduces a midserver as a centralized aggregation point that consolidates data from multiple computing devices before forwarding to the cloud service. This merging approach maintains comprehensive data collection while reducing the number of direct connections to the cloud service, thereby lowering security risks and improving bandwidth efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The midserver acts as an intermediary layer between computing devices and the cloud-based security service. It receives data from multiple devices, performs local filtering and prioritization, and forwards only essential data to the cloud service, thus reducing security exposure while maintaining data collection effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If all network traffic data is transmitted to cloud-based service, then data analysis completeness is improved, but bandwidth consumption increases and network performance deteriorates

Engineering Contradiction:
Improvedata analysis completenessVSAvoidbandwidth consumption
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The midserver implements selective data transmission by filtering and prioritizing network traffic before forwarding to the cloud service. It transmits only the most relevant or suspicious traffic patterns, rather than all raw traffic data, thus maintaining adequate analysis capability while significantly reducing bandwidth consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system extracts and forwards only the essential or anomalous portions of network traffic to the cloud service, leaving routine or benign traffic to be handled locally or discarded. This extraction approach preserves data analysis completeness for critical events while minimizing overall bandwidth usage.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If data collection methods are expanded to cover more devices, then observability is improved, but system complexity and management difficulty increase

Engineering Contradiction:
Improveobservability coverageVSAvoidsystem management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The midserver provides a universal data collection and filtering platform that can handle multiple data sources and protocols through a single system. This multi-functional approach enables expanded observability coverage across diverse devices while maintaining uniform management procedures, thus reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12401629B2System and method for midserver facilitation of mass scanning network traffic detection and analysis
Publication Date: 2025.08.26 QOMPLX INC
  • US12401629B2 patent drawing
  • US12401629B2 patent drawing
  • US12401629B2 patent drawing

AI summary

A system and method that uses midservers located between an enterprise network and an external network to provide mass scanning network traffic detection and analysis capabilities for the enterprise network. The midserver may be loaded with configurations that allow it to operate as a mass scan event detector capable of detecting network sniffers, botnets, and malicious peer-to-peer connections which can lead to security vulnerabilities. In such configurations, midserver may receive and analyze network traffic to determine if the network traffic is suspicious based on heuristic and signature-based techniques, and then generate an appropriate response action which can be implemented to mitigate the risk.