Containerized Network Sensor Deployment for DPI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network sensor deployment paradigms are slow, computing resource intensive, and cumbersome, requiring specialized hardware and knowledge, leading to inefficient deployment and high storage and bandwidth consumption for deep packet inspection (DPI) and network metadata analysis.

Innovation Solution

The deployment of a network sensor package on-premise using a containerized approach, which includes a modified bootstrap, DPI engine, and intrusion detection system, allowing secure communication, configuration, and isolation from the host OS, enabling efficient deployment on multiple Linux distributions with minimal resource usage and automated updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If existing network sensor deployment methodologies are used, then network sensors can be deployed to perform deep packet inspection, but the deployment process is slow and computing resource intensive

Engineering Contradiction:
Improvedeployment speedVSAvoidcomputing resource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent uses virtualization to create virtual copies of network sensor functionality that can be deployed across multiple hosts. The virtual network sensor appliance encapsulates the DPI engine, IDS, and configuration management in a portable virtual image that can be rapidly instantiated without requiring physical hardware deployment, thereby improving deployment speed while reducing per-host computing overhead through shared infrastructure.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a deployment server as an intermediary that automates the entire sensor deployment process. This server manages the provisioning, configuration, and coordination of network sensors across multiple hosts, eliminating manual intervention and reducing deployment time. The deployment server also optimizes resource allocation, preventing excessive computing resource consumption during deployment operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If existing network sensor deployment methodologies are used, then network sensors can be deployed, but specialized hardware and knowledge are required making the process cumbersome

Engineering Contradiction:
Improvedeployment simplicityVSAvoidhardware and knowledge requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates a universal virtual network sensor appliance that can be deployed across diverse hardware platforms and operating systems without requiring specialized hardware or deep technical knowledge. The virtualized sensor package encapsulates all necessary components (DPI engine, IDS, configuration management) in a platform-independent format that can be instantiated on standard infrastructure, thereby simplifying deployment while maintaining functionality across different environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The deployed network sensors automatically perform self-configuration and self-management operations. The sensors autonomously enumerate network interfaces, configure packet capture rules, and manage their own operational parameters without requiring manual intervention or specialized knowledge from operators. This self-service capability dramatically simplifies the deployment process while maintaining robust sensor functionality.

Inventive Principle:
Principle #25Self-service

3Reliability

If existing network sensor deployment methodologies are used, then network metadata can be collected and analyzed, but storage and bandwidth consumption is excessive

Engineering Contradiction:
Improvenetwork metadata analysis qualityVSAvoidstorage and bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent implements local processing and filtering capabilities within the distributed network sensors themselves. Each sensor performs intelligent packet filtering and metadata extraction at the source, analyzing only the specific network traffic relevant to its monitoring scope. This local quality approach ensures high-fidelity network metadata analysis while dramatically reducing the volume of data that needs to be transmitted and stored centrally, thereby lowering storage and bandwidth consumption without sacrificing analysis quality.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12155549B2Managed deployment and configuration of network sensors
Publication Date: 2024.11.26 RAPID7 INC
  • US12155549B2 patent drawing
  • US12155549B2 patent drawing
  • US12155549B2 patent drawing

AI summary

Disclosed herein are methods, systems, and processes for centralized containerized deployment of network traffic sensors to network sensor hosts for deep packet inspection (DPI) that supports various other cybersecurity operations. A network sensor package containing a pre-configured network sensor container is received by a network sensor host from a network sensor deployment server. Installation of the network sensor package on the network sensor host causes execution of the network sensor container that further causes deployment of an on-premise network sensor along with a network sensor management system, a DPI system, and an intrusion detection/prevention (IDS/IPS) system. The configurable on-premise network sensor is deployed on multiple operating system distributions of the network sensor host and generates actionable network metadata using DPI techniques for optimized log search and management and improved intrusion detection and response (IDR) operations.