TDI Filter Denial-of-Service Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for detecting and neutralizing malicious code to prevent denial-of-service attacks require additional hardware and are processing intensive, often leaving servers unable to provide services even after successful detection and neutralization, and may result in increased data latency and reinfection risks.

Innovation Solution

A method and system that analyze network, application, and process data to identify malicious sources, processing subsequent network data to block, redirect, or flow control malicious traffic, using statistical and heuristic techniques within a Transport Data Interface (TDI) filter to prevent denial-of-service attacks without additional hardware, thereby maintaining server functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional packet inspection methods are used to detect malicious code, then malicious code detection capability is improved, but additional hardware is required and processing becomes intensive

Engineering Contradiction:
Improvemalicious code detection capabilityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional hardware-based packet inspection mechanisms with a software-based solution implemented as a filter in the TDI networking stack. This substitution eliminates the need for additional physical hardware while maintaining detection capabilities through software-based analysis of network data, application data, and process data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a TDI filter as an intermediary component within the existing networking stack that mediates between network traffic and the server. This filter analyzes data without requiring separate hardware infrastructure, leveraging the existing system's processing capabilities to detect and block malicious code.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If deep packet inspection techniques are used to detect malicious code, then detection accuracy is improved, but data latency increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis of network data, application data, and process data by integrating the detection filter into the TDI networking stack. This allows data to be analyzed as it passes through the stack rather than requiring assembly of complete payload streams, reducing latency while maintaining detection accuracy through early identification of malicious patterns.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If prior art detection and neutralization methods are used, then malicious code neutralization is achieved, but server service availability deteriorates

Engineering Contradiction:
Improvemalicious code neutralizationVSAvoidserver service availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts and blocks only the malicious portions of network traffic while allowing legitimate traffic to continue flowing to the server. The TDI filter identifies and isolates malicious data packets, preventing them from reaching the server, while maintaining normal service operations for non-malicious traffic, thus preserving server availability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent converts the presence of malicious traffic into a beneficial filtering opportunity. By monitoring and analyzing network data for malicious patterns, the system not only blocks attacks but also gains visibility into threat patterns, improving overall security posture while maintaining service availability through selective blocking.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS8701189B2Method of and system for computer system denial-of-service protection
Publication Date: 2014.04.15 MCAFEE LLC
  • US8701189B2 patent drawing
  • US8701189B2 patent drawing
  • US8701189B2 patent drawing

AI summary

A method of and system for protecting a computer system against denial-of-service attacks or other exploitation. The method comprises collecting network data and analyzing the network data using statistical and heuristic techniques to identify the source of the exploitation upon receiving an indication of exploitation. Upon identifying the network source, the network data associated with the network is blocked, redirected, or flow controlled. Preferably, the method also includes identifying when the system is being exploited.