Multi-Stage Packet Filtering via Automated Rule Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication packet inspection systems lack efficiency and flexibility in filtering large volumes of communication traffic, as they often require manual configuration and do not effectively utilize multi-stage filtering processes to identify and mitigate illegitimate intrusion attempts or data leakage.

Innovation Solution

A multi-stage filtering system comprising a front-end and back-end filtering units, where high-level filtering rules are automatically translated into filtering directives, specifying operations and result delivery between units, enabling efficient filtering of communication packets based on layer-2 to layer-4 attributes and payload content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual configuration is used for packet filtering, then flexibility in rule modification is improved, but system complexity and time consumption increase

Engineering Contradiction:
Improveflexibility in rule modificationVSAvoidtime consumption for configuration
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system automatically translates high-level filtering rules into low-level filtering directives and configures multiple filtering units without manual intervention. The provisioning unit self-configures the filtering system by parsing filtering rules, generating corresponding directives, and distributing them to appropriate filtering units, thereby eliminating manual configuration time while maintaining flexibility through the high-level rule interface.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If multi-stage filtering is implemented, then filtering precision is improved, but device complexity increases

Engineering Contradiction:
Improvefiltering precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The filtering system is divided into multiple filtering units operating at different stages, each handling specific filtering tasks. The front-end filtering unit performs initial filtering on incoming packets, while back-end filtering units perform more complex analysis on selected packets. This segmentation enables precise multi-stage filtering while managing complexity through modular design and automated provisioning.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The provisioning unit acts as an intermediary that automatically translates high-level filtering rules into low-level filtering directives for multiple filtering units. It parses the filtering rules, generates appropriate directives for front-end and back-end filtering units, and manages the configuration complexity, thereby enabling precise multi-stage filtering without requiring manual configuration of each unit.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If automated translation of filtering rules is implemented, then ease of operation is improved, but processing overhead increases

Engineering Contradiction:
Improveease of configurationVSAvoidcomputational overhead
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The system performs automated translation of filtering rules into filtering directives in advance, before actual packet filtering begins. The provisioning unit parses high-level filtering rules, generates optimized low-level directives, and distributes them to filtering units beforehand. This preliminary action simplifies operation by eliminating manual configuration while managing computational overhead by performing the translation work before the filtering process starts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9497167B2System and method for automatic provisioning of multi-stage rule-based traffic filtering
Publication Date: 2016.11.15 COGNYTE TECH ISRAEL LTD
  • US9497167B2 patent drawing
  • US9497167B2 patent drawing
  • US9497167B2 patent drawing

AI summary

Methods and systems for filtering communication packets using a multi-stage filtering system that receives a large volume of communication packets from a communication network that filters the packets in two or more successive stages. The system comprises at least one front-end filtering unit and multiple back-end filtering units. Typically although not necessarily, the front-end filtering unit filters the packets based on layer-2 to layer-4 attributes of the packets. The back-end filtering units, on the other hand, filter the packets based on content extracted from the packet payloads. The back-end filtering units may perform filtering, for example, based on keyword spotting, application classification, malware detection and other content-related criteria. The front-end filtering unit typically performs filtering at the individual packet level and/or at the level of request-response transactions. The back-end filtering units, on the other hand, typically perform filtering at the level of entire reconstructed packet flows.