Network Traffic Traceability via Direct Interconnect and Almanac

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In high-capacity communications networks, determining the traceability of network traffic in real-time is challenging due to the difficulty in authenticating source addresses, leading to issues with payload amplification attacks and network congestion, particularly with stateless transport protocols like DNS, where attackers exploit amplifiers to launch DDoS attacks.

Innovation Solution

A system is implemented that provides a direct interconnect between servers and predefined sources with a private service interface, along with a public service interface, where pairing data is stored as a network traffic almanac to differentiate between legitimate and illegitimate traffic, allowing for dynamic prioritization of request processing based on the interface used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If stateless transport protocols are used for efficient network communication, then network efficiency is improved, but traceability of network traffic deteriorates

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidtraceability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that operates between the stateless transport layer and the application layer. This intermediary verifies source address authenticity without disrupting the efficiency of stateless protocols, thereby maintaining both network efficiency and traceability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication of source addresses before traffic processing. By pre-validating source addresses and establishing trust relationships in advance, the system maintains traceability while allowing efficient stateless transport of authenticated traffic.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If source address authentication is performed to ensure traceability, then traceability is improved, but processing time increases

Engineering Contradiction:
ImprovetraceabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs source address authentication in advance by establishing trust relationships and validating addresses before traffic processing. This preliminary action ensures traceability is established upfront, allowing subsequent traffic to be processed without repeated authentication delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of authentication from per-packet verification to pre-established trust relationships. By transforming the authentication mechanism from a time-intensive per-packet process to a pre-configured parameter validation, traceability is maintained while processing time is reduced.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If all network traffic is processed equally, then network simplicity is maintained, but resource strain increases during attacks

Engineering Contradiction:
Improvenetwork simplicityVSAvoidresource capacity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent applies local quality by treating authenticated and unauthenticated traffic differently. Authenticated traffic receives standard processing while unauthenticated traffic is subjected to additional verification or rate limiting, allowing the network to maintain simplicity for legitimate traffic while protecting resources from attacks.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by applying enhanced processing only to suspicious or unauthenticated traffic rather than all traffic. This selective approach maintains network simplicity for the majority of legitimate traffic while dedicating additional resources to identify and mitigate attack traffic.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If amplification is restricted to constrained clients, then security is improved, but service availability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic amplification restrictions that adapt based on authentication status and traffic patterns. Rather than statically constraining all amplification, the system dynamically allows authenticated clients to use amplification while restricting unauthenticated traffic, thereby maintaining both security and service availability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of amplification from a static restriction to a dynamic permission based on authentication. By transforming amplification from a universally constrained feature to an authenticated capability, the system improves security while maintaining service availability for legitimate users.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11005736B2Determining traceability of network traffic over a communications network
Publication Date: 2021.05.11 IDENTITY DIGITAL LTD
  • US11005736B2 patent drawing
  • US11005736B2 patent drawing
  • US11005736B2 patent drawing

AI summary

A system and method for determining the traceability of network request traffic over a communications network for reducing strain in traffic processing resources, which includes: provisioning a direct interconnect on the communications network between the server and a predefined source, the direct interconnect providing a private service interface, a defined pairings data of the predefined source with the direct interconnect stored as a network traffic almanac; provisioning a public service interface on the communications network; receiving a request traffic having an address of the predefined source via the public service interface; consulting the defined pairing data with the address to determine the request traffic matches the predefined source; and de-prioritizing the processing of the request traffic based on the request traffic being received on the public service interface rather than on the direct interconnect by dynamically applying a prioritize criterion to the second request traffic before generating a response traffic.