Non-Intrusive Cyber Threat Detection via Network Gateway Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber threat detection systems are often intrusive and can be hacked or create vulnerabilities, failing to provide effective early detection, warning, and prevention of cyber attacks in commercial and governmental data networks.

Innovation Solution

A non-intrusive system comprising network gateway servers that collect and analyze metadata via mirrored ports and encrypted communication tunnels, using machine learning and AI to detect vulnerabilities, create behavioral profiles, and block attacks, while maintaining a database of vulnerabilities and providing centralized management and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If intrusive anti-cyber-attack systems are deployed, then detection capability is improved, but system vulnerability increases and network integrity deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidnetwork integrity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system segments the monitoring function from the monitored network by using separate network gateway servers that connect to monitored elements without becoming part of the core network infrastructure. This segmentation allows detection capabilities to be enhanced while preventing the monitoring system itself from becoming a vulnerability or compromising network integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces network gateway servers as intermediary components that bridge the monitoring system and the monitored network elements. These gateways perform handshake protocols and establish encrypted communication tunnels, acting as mediators that enable detection while maintaining isolation and preventing direct access that could compromise network integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If monitoring systems are integrated into the network, then detection effectiveness is improved, but the system creates new vulnerable elements

Engineering Contradiction:
Improvedetection effectivenessVSAvoidnew vulnerabilities
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The monitoring functionality is extracted from the network core and placed in isolated network gateway servers. These gateways collect and analyze data without being critical network components, so if compromised, they do not create vulnerabilities in the core network infrastructure. The extraction separates the detection function from the network elements it monitors.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates an isolated, secure environment for the monitoring gateway servers that are disconnected from the production network. This inert environment allows monitoring operations to proceed without the gateways being able to inject malware or create vulnerabilities in the monitored network, as they operate in a segregated space with controlled access.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Loss of time

If real-time monitoring is implemented, then response time is improved, but system complexity increases

Engineering Contradiction:
Improveresponse timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing encrypted communication tunnels and handshake protocols in advance before monitoring begins. Network gateway servers are pre-configured with security credentials and communication channels, allowing real-time monitoring to start immediately without complex setup during operation, thus reducing response time while managing complexity through upfront configuration.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12069070B2Systems and methods for early detection, warning and prevention of cyber threats
Publication Date: 2024.08.20 AMZEL MOSHE
  • US12069070B2 patent drawing
  • US12069070B2 patent drawing
  • US12069070B2 patent drawing

AI summary

Systems and methods for detection, warning and prevention of cyber-attacks, comprising a first collection layer wherein said network gateway server receive all communication via at least one mirrored port of said monitored network, create a meta-data of said communication and transmit said meta-data via one-way data communication channel to a computing device external to said monitored network; and a second collection wherein said network gateway server use encrypted serial communication tunnel.