Network Traffic Filtering via Anomaly Detection and User Affirmation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Networks with static IP addresses are vulnerable to security attacks and network discovery behaviors, leading to resource wastage and potential intrusions, while broad security policies can disrupt legitimate traffic.

Innovation Solution

A network traffic management system that monitors traffic to detect anomalous patterns, provisionally blocks suspicious sources, and generates filtering rules, allowing user entities to affirm or decline these rules to manage traffic effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If broad security policies are implemented to block suspicious traffic, then network security is improved, but legitimate traffic is disrupted

Engineering Contradiction:
Improvenetwork securityVSAvoidlegitimate traffic flow
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements granular filtering rules that apply security policies to specific sources, destinations, protocols, and ports rather than applying broad blanket blocks. This allows legitimate traffic to pass through while targeting only malicious traffic patterns, resolving the contradiction between security and traffic flow.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The filtering system segments traffic into different categories based on multiple criteria (source IP, destination IP, protocol, port, packet characteristics) and applies different filtering actions to different segments. This segmentation enables precise control that protects security while maintaining legitimate communication channels.

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If network traffic monitoring is implemented to detect anomalous patterns, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveanomalous traffic detectionVSAvoidtraffic management system
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system automatically monitors traffic patterns, detects anomalies, generates filtering rules, and updates itself without requiring manual configuration or intervention. This self-service capability handles the complexity internally while presenting a simple interface to users, resolving the contradiction between detection capability and system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic, compares it against known patterns, and uses the feedback from detected anomalies to automatically generate and refine filtering rules. This closed-loop feedback mechanism enables sophisticated detection without requiring complex manual management.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If static IP addresses are assigned to user equipment, then network accessibility is improved, but vulnerability to security attacks increases

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system preemptively blocks traffic from sources exhibiting malicious patterns before they can exploit the static IP addresses. By detecting and preventing attack patterns in advance, the system protects vulnerable static IP assignments while maintaining their accessibility benefits.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces a network traffic management system as an intermediary between external networks and user equipment with static IPs. This intermediary layer filters and monitors traffic, protecting the static IP addresses from direct exposure to attacks while maintaining their functionality for legitimate access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11711395B2User-determined network traffic filtering
Publication Date: 2023.07.25 VERIZON PATENT & LICENSING INC
  • US11711395B2 patent drawing
  • US11711395B2 patent drawing
  • US11711395B2 patent drawing

AI summary

A device processes a communication between a source and user equipment. The user equipment is one of a plurality of user equipment connected to a network and the user equipment is associated with an entity. The device determines that the communication is associated with an anomalous traffic pattern. The device implements a provisional blocking of traffic between the source and the plurality of user equipment connected to the network and generates a filtering rule based on determining the anomalous traffic pattern, where the filtering rule prescribes that traffic between the source and the second user equipment is to be blocked. The device transmits a notification to the entity associated with the user equipment that requests that the entity affirm the filtering rule, and the device blocks traffic between the source and the user equipment based on the entity affirming the filtering rule.