Automated Network Filtering Rule Regeneration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for updating network traffic filtering rules in cyber-physical systems are time-consuming as they require manual modification of every rule, leading to increased computational overhead and inefficiency.

Innovation Solution

A computer-implemented method and system that automatically regenerate traffic filtering rules by identifying and modifying only the loosest or least secure rules, using a quality metric to split or merge rules, thereby increasing or decreasing the number of rules as needed without revisiting the entire rule set.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual modification of every filtering rule is performed, then the security of the CPS is enhanced, but the time consumption and computational overhead increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the filtering rule set into groups based on similarity metrics, allowing selective regeneration of only those groups that need updating. Instead of manually modifying every rule, the system identifies and processes only the relevant segments, significantly reducing time consumption while maintaining security enhancements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial action by regenerating filtering rules only for selected groups that require updates, rather than processing the entire rule set. This approach uses a quality metric to determine which groups need regeneration, reducing overall processing time while still achieving the necessary security improvements.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If the number of filtering rules is increased to filter out more unwanted traffic, then the security is improved, but the computational overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent merges multiple similar filtering rules into consolidated rules when possible, reducing the total number of rules while maintaining equivalent security coverage. By combining rules that cover similar traffic patterns, the system reduces computational overhead for rule evaluation while preserving the ability to filter unwanted traffic effectively.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the parameters of existing rules through automated regeneration, adjusting rule characteristics to improve security coverage without necessarily increasing the number of rules. This allows the system to enhance security by modifying rule parameters such as source/destination addresses, ports, and protocols, rather than simply adding more rules.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If all existing rules are reevaluated manually, then the quality of filtering is maintained, but the productivity decreases

Engineering Contradiction:
Improvequality of filteringVSAvoidproductivity
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent implements feedback through automated quality metrics that evaluate the effectiveness of filtering rules. The system continuously monitors filtering performance and uses this feedback to automatically regenerate rules only when quality degradation is detected, maintaining high filtering quality without requiring continuous manual reevaluation of all rules.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables self-service through automated rule regeneration using quality metrics and similarity-based grouping. The system automatically identifies rules that need updating, regenerates them based on current traffic patterns and security requirements, and applies the updated rules without human intervention, thereby maintaining filtering quality while significantly improving productivity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10530696B2Systems and methods for generating filtering rules
Publication Date: 2020.01.07 THE BOEING CO
  • US10530696B2 patent drawing
  • US10530696B2 patent drawing
  • US10530696B2 patent drawing

AI summary

Systems and methods for generating filtering rules are provided. One computer implemented method includes receiving a command to modify existing network traffic rules. The method further includes performing a quality calculation for the existing network traffic rules, the quality calculation being a function of a number of distinct flows permitted by a particular rule, wherein (i) if the command to the network is to increase the number of rules, then identifying a rule of the existing network traffic rules with a highest quality calculation, splitting the rule into sub-rules and adding a new rule, and (ii) if the command to the network is to decrease the number of rules, then identifying the existing network traffic rules with quality rule calculations near a predetermined value, adding new rules, and merging the new rules to the identified rules with quality rule calculations near the predetermined value.