Security Engine Audit Rules for Network Address Blocking Accuracy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in accurately and efficiently detecting incorrect IP address blocking due to anomalous behavior caused by malicious computing attacks, which can lead to resource-intensive manual reviews and increased vulnerability.

Innovation Solution

Implementing automated audit rules and a dynamic exclusion macro within security engine audit rules to identify and correct anomalous detection rules, preventing incorrect network address blocking by dynamically removing and reactivating rules that produce abnormal results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated blocking controllers use detection rules to identify malicious network traffic and block IP addresses, then network security is improved, but false positives occur causing correct IP addresses to be incorrectly blocked

Engineering Contradiction:
Improvenetwork securityVSAvoidaccuracy of IP address blocking
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements an integrity check mechanism that continuously monitors detection rules and provides feedback when anomalies are detected. The system compares actual blocking behavior against expected patterns, and when deviations occur (indicating potential false positives), the system automatically triggers rule removal or modification. This closed-loop feedback system enables the system to self-correct and improve accuracy over time while maintaining security.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual review is conducted to rectify incorrect IP address blocking, then accuracy is improved, but time consumption and resource usage increase

Engineering Contradiction:
Improveaccuracy of IP address blockingVSAvoidtime for manual review
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a self-service mechanism where the system automatically detects, diagnoses, and corrects incorrect IP address blocking without human intervention. The integrity check mechanism autonomously monitors detection rules, identifies anomalies through automated analysis, and executes corrective actions such as removing or modifying problematic rules. This self-correcting capability eliminates the need for time-consuming manual reviews while maintaining high accuracy in IP address blocking.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If detection rules are continuously monitored and audited, then false positives are reduced, but system complexity increases

Engineering Contradiction:
Improveaccuracy of IP address blockingVSAvoidcomplexity of security system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the complexity of continuous monitoring and audit functions into a separate, dedicated integrity check mechanism. Rather than embedding complex monitoring logic throughout the entire security system, the patent isolates the audit functionality into a distinct module that specifically handles detection rule monitoring, anomaly detection, and corrective actions. This extraction reduces the complexity burden on the main security system while maintaining the benefits of continuous monitoring.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250106245A1Security engine audit rules to prevent incorrect network address blocking
Publication Date: 2025.03.27 PAYPAL INC
  • US20250106245A1 patent drawing
  • US20250106245A1 patent drawing
  • US20250106245A1 patent drawing

AI summary

Systems and methods for security engine audit rules to prevent incorrect network address blocking are disclosed. An entity such as a service provider may determine network traffic logs caused or generated by malicious web traffic and network communications, such as during a computing attack by a bad actor. The service provider may implement automated blocking controllers, which use detection rules to detect the malicious network traffic, and thereafter generate a network address blocklist that is distributed to devices, components, and servers of the service provider for network address blocking. To ensure the integrity of the detection rules, audit rules and a dynamic exclusion macro may be executed to detect when a detection rule is behaving abnormally and/or leading to anomalous results. If a detection rule is not properly blocking network addresses, the rule may be removed from execution until recovery.