Packet Inspection Load Control via Dynamic Threshold Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional packet inspection apparatuses face difficulties in distinguishing between malicious and normal service requests during DoS attacks, leading to increased processing time and potential system overload, which can result in service interruptions and prolonged waiting times for normal packets.

Innovation Solution

A method that classifies incoming packets based on simple header information to determine whether they should be blocked or passed through the packet inspection apparatus, using dynamic threshold values to control the load and prevent overload, thereby reducing the burden on the system and maintaining functionality during DoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full packet inspection is performed on all incoming packets, then security detection capability is improved, but system overload occurs during DoS attacks and service waiting time increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidservice waiting time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by performing load measurement and packet classification before the main packet inspection process. When the packet flow exceeds the upper limit value, the system preemptively classifies packets using simple header information and blocks suspicious packets before they reach the full inspection apparatus, preventing overload before it occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the packet handling process into two distinct paths: a fast path for packets within normal load limits that undergo full inspection, and a blocked path for packets exceeding the upper limit value that are quickly classified and blocked based on header information only. This segmentation allows the system to maintain security for normal traffic while protecting against overload during attacks.

Inventive Principle:
Principle #1Segmentation

2Reliability

If dynamic threshold adjustment is implemented to control load, then system survivability during DoS attacks is improved, but device complexity increases

Engineering Contradiction:
Improvesystem survivabilityVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback by continuously measuring the current packet flow amount and comparing it against upper and lower limit values. Based on this feedback, the system dynamically adjusts its behavior: when flow exceeds the upper limit, it activates load control mode with simplified packet handling; when flow drops below the lower limit, it returns to normal full inspection mode. This feedback mechanism enables automatic adaptation to attack conditions without manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies dynamics by making the packet inspection system adaptable and flexible through dynamic threshold adjustment. The upper limit value and lower limit value are not fixed but can be adjusted based on system capacity and attack conditions. This allows the system to dynamically change its operational characteristics to maintain survivability under varying load conditions while managing complexity through automated control logic.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8719916B2Method and apparatus for controlling loads of a packet inspection apparatus
Publication Date: 2014.05.06 THE IND & ACADEMIC COOP IN CHUNGNAM NAT UNIV (IAC)
  • US8719916B2 patent drawing
  • US8719916B2 patent drawing
  • US8719916B2 patent drawing

AI summary

The present invention periodically monitors the amount of packets flowing into a packet inspection apparatus, i.e., a load level, and compares the load level with a predetermined upper or lower limit value. Accordingly, the present invention blocks some of the packets or passes along some of the packets through the packet inspection apparatus when the load level exceeds a certain level, and thus the load controlling method and apparatus guarantees continuous operation of the packet inspection apparatus even in an overloaded state. In addition, the load controlling method and apparatus according to the present invention effectively selects packets to be blocked or passed without departing from the original functions of the packet inspection apparatus. The load controlling method and apparatus is configured simply so as not to additionally induce a load in the process of selection, and the load controlling apparatus selectively operates only in an overloaded state.