TDI Filter Denial-of-Service Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for detecting and neutralizing malicious code to prevent denial-of-service attacks require additional hardware and are processing intensive, often leaving servers unable to provide services even after successful detection and neutralization, and may result in increased data latency and reinfection risks.
Innovation Solution
A method and system that analyze network, application, and process data to identify malicious sources, processing subsequent network data to block, redirect, or flow control malicious traffic, using statistical and heuristic techniques within a Transport Data Interface (TDI) filter to prevent denial-of-service attacks without additional hardware, thereby maintaining server functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional packet inspection methods are used to detect malicious code, then malicious code detection capability is improved, but additional hardware is required and processing becomes intensive
Solution Approach 1:
The patent replaces traditional hardware-based packet inspection mechanisms with a software-based solution implemented as a filter in the TDI networking stack. This substitution eliminates the need for additional physical hardware while maintaining detection capabilities through software-based analysis of network data, application data, and process data.
Solution Approach 2:
The patent introduces a TDI filter as an intermediary component within the existing networking stack that mediates between network traffic and the server. This filter analyzes data without requiring separate hardware infrastructure, leveraging the existing system's processing capabilities to detect and block malicious code.
2Measurement precision
If deep packet inspection techniques are used to detect malicious code, then detection accuracy is improved, but data latency increases
Solution Approach 1:
The patent performs preliminary analysis of network data, application data, and process data by integrating the detection filter into the TDI networking stack. This allows data to be analyzed as it passes through the stack rather than requiring assembly of complete payload streams, reducing latency while maintaining detection accuracy through early identification of malicious patterns.
3Reliability
If prior art detection and neutralization methods are used, then malicious code neutralization is achieved, but server service availability deteriorates
Solution Approach 1:
The patent extracts and blocks only the malicious portions of network traffic while allowing legitimate traffic to continue flowing to the server. The TDI filter identifies and isolates malicious data packets, preventing them from reaching the server, while maintaining normal service operations for non-malicious traffic, thus preserving server availability.
Solution Approach 2:
The patent converts the presence of malicious traffic into a beneficial filtering opportunity. By monitoring and analyzing network data for malicious patterns, the system not only blocks attacks but also gains visibility into threat patterns, improving overall security posture while maintaining service availability through selective blocking.
Data Source
AI summary
A method of and system for protecting a computer system against denial-of-service attacks or other exploitation. The method comprises collecting network data and analyzing the network data using statistical and heuristic techniques to identify the source of the exploitation upon receiving an indication of exploitation. Upon identifying the network source, the network data associated with the network is blocked, redirected, or flow controlled. Preferably, the method also includes identifying when the system is being exploited.


