Network Traffic Monitoring via Dynamic Trust Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional communication networks face challenges in accurately monitoring and blocking network traffic, often resulting in false positives or negatives due to crude, manual, or pre-determined methods, which are costly and inefficient.
Innovation Solution
A system that determines the trustworthiness of network elements by generating and comparing hash values, allowing for selective traffic monitoring and blocking based on a degree of trust, using rules, pattern matching, and deviation from expected values techniques, with human expert interface input for adaptation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic monitoring is done in an all or nothing fashion manually, then traffic security is improved, but operational cost increases
Solution Approach 1:
The patent segments traffic monitoring into multiple levels based on trust scores. Network elements are divided into trusted (high score) and untrusted (low score) categories, allowing differentiated monitoring intensity. This segmentation enables automated systems to focus resources on high-risk traffic while reducing manual intervention for low-risk traffic, thereby improving security without proportionally increasing operational costs.
Solution Approach 2:
The patent implements dynamic trust scoring that continuously updates based on observed traffic patterns and behavior. The monitoring intensity adapts dynamically to the trust score - high-trust elements receive minimal monitoring while low-trust elements receive intensive scrutiny. This dynamic approach replaces static manual monitoring with adaptive automated monitoring, improving security coverage while reducing operational costs.
2Ease of operation
If automated traffic monitoring is done in a pre-determined fashion, then operational cost is reduced, but measurement precision deteriorates due to false positives and negatives
Solution Approach 1:
The patent applies local quality by tailoring the monitoring precision to each network element's specific trust score. Instead of uniform pre-determined monitoring rules, the system adjusts monitoring depth, inspection intensity, and analysis granularity based on individual element characteristics. High-trust elements receive streamlined monitoring while low-trust elements receive comprehensive scrutiny, improving measurement precision without excessive operational costs.
Solution Approach 2:
The patent changes monitoring parameters dynamically based on trust scores. The system adjusts inspection depth, packet sampling rates, protocol analysis intensity, and rule application strictness according to the trust level of each network element. This parameter adaptation allows automated monitoring to achieve high precision by intensifying analysis only where necessary, reducing false positives and negatives while maintaining operational efficiency.
3Reliability
If intensive traffic monitoring is applied to all network elements, then traffic security is improved, but productivity deteriorates due to processing overhead
Solution Approach 1:
The patent applies partial monitoring action by intensifying scrutiny only for the portion of traffic from low-trust network elements while using minimal monitoring for high-trust elements. Instead of applying excessive monitoring uniformly to all traffic, the system applies just enough monitoring intensity to each element based on its trust score. This partial action approach maintains security for untrusted traffic while preserving network throughput for trusted traffic.
Solution Approach 2:
The patent extracts high-trust network elements from intensive monitoring and places them in a streamlined processing path. By identifying and separating trusted traffic from untrusted traffic through trust scoring, the system removes the overhead of intensive monitoring from legitimate traffic while maintaining security scrutiny on suspicious traffic. This extraction preserves network productivity while maintaining security through targeted monitoring of only the necessary portion of traffic.
Data Source
AI summary
A communication network is operated by determining whether a network element can be trusted and monitoring traffic associated with the network element based on whether the network element can be trusted. At least some of the monitored traffic may be selected for examination based on the degree of trust for the network element. At least some of the monitored and/or examined traffic is selected to be blocked based on the degree of trust for the network element.


