Non-Intrusive Cyber Threat Detection via Network Gateway Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber threat detection systems are often intrusive and can be hacked or create vulnerabilities, failing to provide effective early detection, warning, and prevention of cyber attacks in commercial and governmental data networks.
Innovation Solution
A non-intrusive system comprising network gateway servers that collect and analyze metadata via mirrored ports and encrypted communication tunnels, using machine learning and AI to detect vulnerabilities, create behavioral profiles, and block attacks, while maintaining a database of vulnerabilities and providing centralized management and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If intrusive anti-cyber-attack systems are deployed, then detection capability is improved, but system vulnerability increases and network integrity deteriorates
Solution Approach 1:
The system segments the monitoring function from the monitored network by using separate network gateway servers that connect to monitored elements without becoming part of the core network infrastructure. This segmentation allows detection capabilities to be enhanced while preventing the monitoring system itself from becoming a vulnerability or compromising network integrity.
Solution Approach 2:
The patent introduces network gateway servers as intermediary components that bridge the monitoring system and the monitored network elements. These gateways perform handshake protocols and establish encrypted communication tunnels, acting as mediators that enable detection while maintaining isolation and preventing direct access that could compromise network integrity.
2Measurement precision
If monitoring systems are integrated into the network, then detection effectiveness is improved, but the system creates new vulnerable elements
Solution Approach 1:
The monitoring functionality is extracted from the network core and placed in isolated network gateway servers. These gateways collect and analyze data without being critical network components, so if compromised, they do not create vulnerabilities in the core network infrastructure. The extraction separates the detection function from the network elements it monitors.
Solution Approach 2:
The system creates an isolated, secure environment for the monitoring gateway servers that are disconnected from the production network. This inert environment allows monitoring operations to proceed without the gateways being able to inject malware or create vulnerabilities in the monitored network, as they operate in a segregated space with controlled access.
3Loss of time
If real-time monitoring is implemented, then response time is improved, but system complexity increases
Solution Approach 1:
The system performs preliminary actions by establishing encrypted communication tunnels and handshake protocols in advance before monitoring begins. Network gateway servers are pre-configured with security credentials and communication channels, allowing real-time monitoring to start immediately without complex setup during operation, thus reducing response time while managing complexity through upfront configuration.
Data Source
AI summary
Systems and methods for detection, warning and prevention of cyber-attacks, comprising a first collection layer wherein said network gateway server receive all communication via at least one mirrored port of said monitored network, create a meta-data of said communication and transmit said meta-data via one-way data communication channel to a computing device external to said monitored network; and a second collection wherein said network gateway server use encrypted serial communication tunnel.


