Midserver Traffic Aggregation for Mass Scan Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large business enterprises face challenges in managing data collection, security, and network traffic analysis due to heterogeneous data transfer, lack of reliable data collection methods, poor protocol support, security concerns, and inefficient bandwidth usage, especially when using cloud-based services, leading to unorganized data management and increased security risks.
Innovation Solution
A midserver-based system is introduced to detect and analyze network traffic, equipped with sensors and containerized services to collect, aggregate, analyze, and securely transmit data, reducing network connections and enhancing security by identifying threats like botnets and malicious connections using heuristic and signature-based techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If each computing device sends data to cloud-based service on separate connections, then data collection coverage is improved, but network security risks increase and bandwidth efficiency deteriorates
Solution Approach 1:
The patent introduces a midserver as a centralized aggregation point that consolidates data from multiple computing devices before forwarding to the cloud service. This merging approach maintains comprehensive data collection while reducing the number of direct connections to the cloud service, thereby lowering security risks and improving bandwidth efficiency.
Solution Approach 2:
The midserver acts as an intermediary layer between computing devices and the cloud-based security service. It receives data from multiple devices, performs local filtering and prioritization, and forwards only essential data to the cloud service, thus reducing security exposure while maintaining data collection effectiveness.
2Loss of information
If all network traffic data is transmitted to cloud-based service, then data analysis completeness is improved, but bandwidth consumption increases and network performance deteriorates
Solution Approach 1:
The midserver implements selective data transmission by filtering and prioritizing network traffic before forwarding to the cloud service. It transmits only the most relevant or suspicious traffic patterns, rather than all raw traffic data, thus maintaining adequate analysis capability while significantly reducing bandwidth consumption.
Solution Approach 2:
The system extracts and forwards only the essential or anomalous portions of network traffic to the cloud service, leaving routine or benign traffic to be handled locally or discarded. This extraction approach preserves data analysis completeness for critical events while minimizing overall bandwidth usage.
3Adaptability or versatility
If data collection methods are expanded to cover more devices, then observability is improved, but system complexity and management difficulty increase
Solution Approach 1:
The midserver provides a universal data collection and filtering platform that can handle multiple data sources and protocols through a single system. This multi-functional approach enables expanded observability coverage across diverse devices while maintaining uniform management procedures, thus reducing overall system complexity.
Data Source
AI summary
A system and method that uses midservers located between an enterprise network and an external network to provide mass scanning network traffic detection and analysis capabilities for the enterprise network. The midserver may be loaded with configurations that allow it to operate as a mass scan event detector capable of detecting network sniffers, botnets, and malicious peer-to-peer connections which can lead to security vulnerabilities. In such configurations, midserver may receive and analyze network traffic to determine if the network traffic is suspicious based on heuristic and signature-based techniques, and then generate an appropriate response action which can be implemented to mitigate the risk.


