Network Security System Traffic Flow Shaping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing systems providing services over networks are susceptible to malicious access, overwhelming existing network security systems due to coordinated and sophisticated access attempts, which can exhaust their resources.

Innovation Solution

A network security system is added upstream to manage sender demand by shaping network traffic flow and misinforming senders, reducing resource demand through techniques like dropping or deflecting traffic, slowing communication, and providing misinformation to deter malicious access attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security systems block malicious traffic, then security is improved, but system resources are exhausted

Engineering Contradiction:
ImprovesecurityVSAvoidsystem resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system performs preliminary actions by analyzing traffic patterns and identifying malicious senders before they can exhaust system resources. The network security system proactively manages sender demand by shaping traffic flows and providing misinformation to deter malicious access attempts, preventing resource exhaustion before it occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network security system acts as an intermediary between malicious senders and the computing services system. It intercepts and manages traffic flows, shaping them to reduce demand on protected systems while maintaining security. The intermediary manages the balance between blocking malicious traffic and preserving legitimate communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If network security systems respond to all traffic, then detection capability is improved, but system performance deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem performance
Core Design Contradiction:
Difficulty of detecting and measuringVSProductivity

Solution Approach 1:

The system applies partial action by selectively responding to traffic based on sender identification and pattern analysis. Rather than responding to all traffic equally, it prioritizes detection and response to malicious senders while reducing response to benign traffic, thereby maintaining detection capability while improving overall system performance.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes operational parameters dynamically based on traffic conditions and sender behavior. It adjusts response strategies, shaping parameters, and misinformation levels based on real-time analysis of traffic patterns, allowing the system to optimize both detection capability and performance under varying conditions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11683327B2Demand management of sender of network traffic flow
Publication Date: 2023.06.20 MICRO FOCUS LLC
  • US11683327B2 patent drawing
  • US11683327B2 patent drawing
  • US11683327B2 patent drawing

AI summary

A network traffic flow is directed to a computing services system is determined as being unrelated to the service that the system provides. In response, the network traffic flow is deflected away from the computing services system. Demand of the sender of the network traffic flow is managed by shaping the deflected network traffic flow in responding to the sender and/or by misinforming the sender in responding to the sender.