Plug-and-play network filter appliance for autonomous traffic interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Parents lack a simple, non-technical solution to control Internet access for new devices connected to their networks, as existing browser-based and software-based filters do not effectively address this issue.
Innovation Solution
A plug-and-play network filter appliance that connects to a network, alters traffic flow by issuing gratuitous ARP packets, and filters outbound Internet traffic, allowing it to intercept and manage packets between end-user terminals and routers, enabling logging, blocking, and forwarding of allowed traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If browser-based or software-based filters are used, then filtering capability is provided, but they do not address new devices connected to the network and require technical capability
Solution Approach 1:
The network filter appliance automatically performs ARP spoofing and traffic interception without requiring user configuration. When connected to the network, it autonomously redirects traffic from new devices through its filtering mechanisms, eliminating the need for manual setup or technical knowledge while maintaining adaptability to any newly connected device.
Solution Approach 2:
The appliance inserts itself as an intermediary between end devices and the router by sending gratuitous ARP packets. This intermediary position allows it to capture and filter traffic from all devices on the network, including new devices, without requiring those devices or the router to be configured, thus providing both ease of use and universal adaptability.
2Ease of operation
If network management systems with user control are implemented, then access control capability is improved, but device complexity increases
Solution Approach 1:
The appliance autonomously manages network traffic interception and filtering without requiring complex configuration interfaces or user intervention. It automatically detects new devices, redirects their traffic through ARP spoofing, and applies filtering rules, thereby maintaining user control capability while minimizing system complexity and ease of deployment.
Solution Approach 2:
The patent extracts the complex network management functionality into a dedicated standalone appliance, separating it from the main router and end devices. This extraction allows the router and end devices to remain simple while the specialized appliance handles all complex filtering and traffic management operations, reducing overall system complexity while maintaining control capability.
3Productivity
If ARP spoofing is used to intercept traffic, then traffic filtering capability is improved, but network transparency may be compromised
Solution Approach 1:
The appliance positions itself as an intermediary in the network path by sending gratuitous ARP packets that redirect traffic through itself. This intermediary position enables effective traffic filtering while maintaining network transparency, as the appliance can forward filtered traffic back to the original destination without devices detecting the interception, thus balancing filtering effectiveness with network transparency.
Data Source
AI summary
A method of filtering outbound Internet traffic includes connecting an appliance to a network (that includes an end user terminal and a router), altering the flow of network traffic to direct the end user terminal to route outbound Internet traffic through the appliance, and filtering the outbound Internet traffic with the appliance. The outbound Internet traffic is traffic to remote servers from the end user terminal. The appliance may alter the flow of network traffic by issuing a gratuitous ARP packet from the appliance to direct the end user terminal to route the outbound Internet traffic through the appliance instead of the router. The appliance may receive the outbound Internet traffic to remote servers from the end user terminal, monitor the outbound Internet traffic, filter the outbound Internet traffic to form allowed packets for the remote servers, and/or forward the allowed packets to the remote servers.


