Packet Relay Apparatus Attack Traffic Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current packet relay systems are unable to effectively refine and transfer packets into multiple analyzers suited for different attack types, leading to excessive load on analyzers and inefficient analysis performance during large-scale attacks.

Innovation Solution

A packet relay apparatus that includes a packet receiving module, a security judgment module, and a mirror processing module to identify and replicate only attack-related packets, allowing these packets to be transmitted to specific analyzers, thereby reducing the load on the analyzers and optimizing analysis by refining and dividing packets based on attack types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all packets are transferred to analyzers for analysis, then complete traffic monitoring is achieved, but the load on analyzers becomes excessive and analysis performance deteriorates

Engineering Contradiction:
Improvetraffic monitoring completenessVSAvoidanalyzer processing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The packet flow is segmented into multiple categories based on attack type detection (DDoS, logic attacks, spoofing, etc.), and each segment is directed to appropriate analyzers. This divides the workload and enables selective analysis based on packet characteristics, resolving the contradiction between monitoring completeness and analyzer capacity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Only packets that show attack signs or belong to specific attack types are extracted and transferred to analyzers, while normal traffic is filtered out. This extraction mechanism maintains monitoring reliability for critical packets while reducing the overall load on analyzers.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If multiple analyzers are coupled to handle different attack types, then attack analysis coverage is improved, but device complexity increases

Engineering Contradiction:
Improveattack type coverageVSAvoidanalyzer coupling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The packet relay apparatus performs multiple functions: it monitors traffic, detects attack signs, classifies attack types, and directs packets to appropriate analyzers. This multi-functionality reduces the need for separate dedicated systems for each function, thereby managing complexity while achieving comprehensive attack coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The packet relay apparatus acts as an intermediary between the network traffic and multiple analyzers. It receives all packets, performs preliminary analysis and classification, then selectively forwards packets to relevant analyzers. This intermediary role simplifies the overall system architecture by centralizing the decision-making logic in the relay apparatus.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If packets are screened and divided among multiple analyzers, then analysis efficiency is improved, but the screening method must be optimized for each attack type

Engineering Contradiction:
Improveanalysis efficiencyVSAvoidscreening method complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The packet relay apparatus performs preliminary analysis and classification of packets before they reach the analyzers. It pre-determines attack types and directs packets accordingly, so that analyzers receive only pre-sorted packets. This preliminary action improves analysis efficiency while the screening complexity is managed within the relay apparatus rather than each analyzer.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10693890B2Packet relay apparatus
Publication Date: 2020.06.23 FORTINET INC
  • US10693890B2 patent drawing
  • US10693890B2 patent drawing
  • US10693890B2 patent drawing

AI summary

A packet relay apparatus, which is configured to transmit from a mirror port a mirror packet copied from one of a packet to be received and a packet to be transmitted, the packet relay apparatus comprising: a packet receiving module configured to receive a packet from an input port; a security judgment module configured to judge whether or not the packet is possibly one of an attack and an attack sign; a mirror processing module configured to generate, when it is judged that the packet is possibly one of an attack and an attack sign, a replica of the packet as the mirror packet; and a transmitting module configured to transmit the mirror packet from the mirror port.