Network Protection Service for Adverse Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face challenges in protecting their online presence from adverse network conditions such as DoS, DDoS, and legitimate traffic spikes, which can overwhelm their network processing capacity, leading to service disruptions and high costs in maintaining reserve bandwidth.
Innovation Solution
A network protection service that analyzes traffic, filters and reroutes network traffic, and provides processing assistance to subscribing hosts during adverse conditions, using high-capacity computing devices and dynamic resource allocation to ensure continuous service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If companies maintain reserve bandwidth to handle adverse network conditions, then service availability is improved, but costs increase
Solution Approach 1:
The patent introduces a network protection service as an intermediary between the network site and adverse traffic conditions. This service monitors network conditions, detects adverse patterns, and filters malicious traffic before it reaches the network site, thereby maintaining service availability without requiring the site itself to maintain expensive reserve bandwidth
Solution Approach 2:
The network protection service performs preliminary monitoring and detection of network conditions before adverse conditions fully impact the network site. By detecting signs of DoS attacks, traffic spikes, or other adverse conditions in advance, the service can prepare filtering rules and redirect traffic proactively, preventing service disruption without needing permanent reserve capacity
2Reliability
If companies use protective software and hardware to block malware, then security is improved, but legitimate traffic may be blocked
Solution Approach 1:
The network protection service implements continuous monitoring of network traffic patterns and uses feedback loops to dynamically adjust filtering rules. By analyzing traffic characteristics in real-time, the service can distinguish between malicious and legitimate traffic, blocking threats while allowing legitimate traffic to pass through without interruption
Solution Approach 2:
The service applies different filtering strategies to different types of traffic based on their characteristics. Rather than using a blanket blocking approach, the system tailors its response to each traffic pattern, applying strict filtering to suspected malicious traffic while maintaining permissive passage for legitimate traffic patterns
3Reliability
If companies maintain protective shields against malware, then security is improved, but costs of maintaining and updating protection increase
Solution Approach 1:
The network protection service acts as an external intermediary that handles the burden of security monitoring and filtering, freeing the network site from maintaining its own extensive protective infrastructure. The service provider bears the cost and complexity of maintaining security rules, updates, and monitoring capabilities
Solution Approach 2:
The network protection service autonomously monitors network conditions, detects threats, and adjusts filtering rules without requiring continuous human intervention. The system self-manages the protection infrastructure, automatically updating its capabilities and maintaining security without requiring the network site to invest resources in manual protection management
Data Source
AI summary
A network protection service for providing protective assistance to a subscribing host is presented. The network protection service is configured determine a set of rules for filtering network traffic for a subscribing host. The network protection service is further configured to receive network traffic on behalf of the subscribing host, filter the received network traffic according to the set of rules, and forward a portion of the filtered network traffic to the subscribing host. Still further, the network protection service is configured to analyze the received network traffic via the analysis server, and refine the set of rules for filtering the received network traffic based on the analysis of the received network traffic by the analysis server.


