Multi-Layer Malicious Traffic Filtering for Multi-Vector Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods are inadequate in mitigating multi-vector cyberattacks that utilize multiple entry points and methods, leading to excessive network expansion and costly, manual reconfiguration, and are unable to effectively block malicious traffic before it affects legitimate traffic.

Innovation Solution

A multi-layered approach involving ingress filtering, source-based data rate limiting, access control, network data rate limiting, and deep packet analysis is implemented at each layer to detect and mitigate malicious network traffic, blocking it at its source without impacting legitimate traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If conventional malicious traffic mitigation systems are used to detect and block cyberattacks, then specific network entry points can be addressed, but the systems cannot engage mitigation fast enough to prevent damaging effects from multi-vector cyberattacks

Engineering Contradiction:
Improvemitigation speedVSAvoidprotection effectiveness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments malicious traffic mitigation into multiple independent layers operating at different OSI levels (L3-L7). Each layer handles specific attack vectors independently, allowing parallel processing and faster response times. The segmentation enables the system to address multi-vector cyberattacks simultaneously across multiple network points without sequential bottlenecks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary classification and filtering of network traffic at ingress points before malicious traffic can propagate through the network. By pre-identifying and blocking malicious packets early in the traffic flow, the system prevents damaging effects before they occur, rather than reacting after detection.

Inventive Principle:
Principle #10Preliminary action

2Quantity of substance

If networks are provisioned with excess high-bandwidth communication channels to account for malicious traffic, then network capacity is sufficient to handle attacks, but this is an extremely costly endeavor

Engineering Contradiction:
Improvenetwork bandwidth capacityVSAvoidnetwork provisioning cost
Core Design Contradiction:
Quantity of substanceVSLoss of energy

Solution Approach 1:

The patent extracts and removes malicious traffic from the network stream at multiple points, separating harmful packets from legitimate traffic. This extraction approach allows the network to operate at optimal capacity without requiring excess bandwidth provisioning, as malicious traffic is continuously removed rather than accommodated.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system dynamically adjusts traffic filtering parameters and thresholds based on detected attack patterns and network conditions. By changing operational parameters rather than physical infrastructure capacity, the network can adapt to varying attack intensities without costly expansions.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If conventional systems require constant and manual reconfiguring of network devices in response to varying cyberattack vectors, then the systems can adapt to new threats, but this is overly daunting, error-prone, time-consuming, and ultimately ineffective

Engineering Contradiction:
Improveresponse to varying attack vectorsVSAvoidreconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements dynamic, automated adjustment of mitigation parameters across multiple network devices. The system continuously adapts to new attack vectors through automated policy updates and parameter tuning, eliminating manual reconfiguration while maintaining high adaptability to varying threat landscapes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops that monitor attack patterns and automatically adjust mitigation strategies. By using real-time feedback from traffic analysis and threat detection, the system self-adapts to new cyberattack vectors without human intervention, reducing both time loss and error rates associated with manual reconfiguration.

Inventive Principle:
Principle #23Feedback

4Object-affected harmful factors

If multi-layered traffic filtering is implemented to block malicious packets, then malicious traffic is effectively blocked, but legitimate traffic may be impacted

Engineering Contradiction:
Improvemalicious traffic blockingVSAvoidlegitimate traffic impact
Core Design Contradiction:
Object-affected harmful factorsVSObject-generated harmful factors

Solution Approach 1:

The patent applies different filtering criteria and inspection depths to different types of traffic based on local characteristics. By tailoring the strictness and type of filtering to specific traffic patterns, protocols, and sources, the system effectively blocks malicious traffic while preserving legitimate communications that match established profiles.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial filtering actions to different traffic streams simultaneously, using less stringent rules for trusted traffic and more stringent rules for suspicious traffic. This differentiated approach ensures thorough blocking of malicious packets while minimizing impact on legitimate traffic through selective application of filtering intensity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12381898B2Mitigating malicious network traffic
Publication Date: 2025.08.05 FRONTIER COMMUNICATIONS HOLDINGS LLC
  • US12381898B2 patent drawing
  • US12381898B2 patent drawing
  • US12381898B2 patent drawing

AI summary

Disclosed herein are system, method, and computer program product embodiments for mitigating malicious network traffic. A computing device (e.g., a network management device, a control device, etc.) may receive indications of data/information communicated by one or more devices within a network and cause the one or more devices to implement measures to block malicious traffic resulting from multi-vector cyberattacks.