Deep Packet Analysis via Segmented Engine Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security devices face bottlenecks in handling increasing network traffic volumes and complex security attacks, leading to high latency and resource inefficiencies, as they are not optimized for deep packet analysis and often require hardware with fast CPUs and large memory, causing significant costs and inefficiencies.

Innovation Solution

A computer-implemented method and system that distributes deep packet analysis between a network analysis engine and a host-based analysis engine, using a sandbox environment to process incoming data packets, allowing for caching and parallel processing, thereby reducing the load on individual devices and optimizing deep packet inspection by selecting representative packets for analysis, and ensuring security without overwhelming the network analysis engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep packet analysis is performed on all incoming network traffic, then security detection capability is improved, but network packet analysis latency increases and processing resources are exhausted

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidnetwork packet analysis latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the packet analysis process into two distinct engines: a network analysis engine that performs initial deep packet analysis on representative samples, and a host-based analysis engine that handles additional processing. This segmentation allows the system to maintain high security detection capability while reducing latency by distributing the processing load rather than concentrating all analysis in a single location.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by analyzing only representative packets rather than every single packet in detail. The network analysis engine selects representative packets from incoming traffic and performs deep packet analysis on these samples, which provides sufficient security detection capability without the excessive processing time and resource consumption that would result from analyzing all packets exhaustively.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If deep packet analysis is performed on all incoming network traffic, then security detection capability is improved, but processing resources and hardware costs increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidprocessing resources and hardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the processing workload between a network analysis engine and a host-based analysis engine. The network analysis engine handles the resource-intensive deep packet analysis of representative samples, while the host-based engine performs additional processing tasks. This segmentation reduces the hardware requirements for any single device while maintaining overall security detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

By performing deep packet analysis only on representative packets rather than all packets, the patent significantly reduces the processing resources and hardware costs required. This partial action approach maintains sufficient security detection capability while avoiding the excessive resource consumption that would be necessary for exhaustive analysis of all incoming traffic.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If representative packets are selected for analysis, then processing efficiency is improved, but analysis completeness may be compromised

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidanalysis completeness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the analysis process into two stages: first, the network analysis engine selects representative packets and performs initial deep packet analysis; second, the host-based analysis engine performs additional analysis on the representative packets. This segmentation ensures that processing efficiency is improved through representative sampling while analysis completeness is maintained through the two-stage verification process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback mechanisms where the network analysis engine provides results to the host-based analysis engine, and the host-based engine can request additional analysis on specific representative packets. This feedback loop ensures that processing efficiency is maintained through representative sampling while analysis completeness is verified through iterative review and validation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11757912B2Deep packet analysis
Publication Date: 2023.09.12 KYNDRYL INC
  • US11757912B2 patent drawing
  • US11757912B2 patent drawing
  • US11757912B2 patent drawing

AI summary

A computer-implemented method for protecting a processing environment from malicious incoming network traffic may be provided. The method comprises: in response to receiving incoming network traffic comprising a data packet, performing a packet and traffic analysis of the data packet to determine whether said data packet is non-malicious and malicious, and processing of the data packet in a sandbox environment. Furthermore, the method comprises: in response to detecting that the data packet is non-malicious based on the packet and traffic analysis, releasing the processed data packet from the sandbox environment for further processing in the processing environment, and in response to detecting that the data packet is malicious based on the packet and traffic analysis discarding the data packet.