Dynamic Cloud Threat Detection via Adaptive Packet Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home and mobile networks are increasingly vulnerable to cyber-attacks due to the growing number of devices and lack of basic cybersecurity measures, with existing threat detection solutions being ineffective in identifying malicious traffic, especially from new or changing sources, and requiring extensive resources that are not feasible in residential environments.

Innovation Solution

A dynamic cloud-based threat detection system that uses packet inspection to analyze communication sessions by selecting a predefined number of packets for inspection based on packet selection rules, which are updated based on internal and external factors, allowing for efficient and resource-friendly detection of cyber threats without disrupting network performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If packet inspection is performed on all communication traffic to improve threat detection accuracy, then detection precision improves, but network performance deteriorates and resource consumption increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system inspects only a predefined number of packets from each communication session rather than all packets. This partial inspection approach maintains adequate threat detection capability while significantly reducing the processing load on the network, thereby preserving network performance and reducing resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The communication traffic is segmented into individual packets, and the system selectively inspects a predefined subset of these packets from each session. This segmentation allows the system to manage inspection workload efficiently while maintaining detection effectiveness across multiple communication sessions.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If packet inspection is performed on all communication traffic to improve threat detection accuracy, then detection precision improves, but resource consumption increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system inspects only a predefined number of packets from each communication session rather than all packets. This partial inspection approach maintains adequate threat detection capability while significantly reducing the processing load and resource consumption required for security monitoring.

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If a fixed number of packets are inspected for each communication session, then system complexity is reduced, but adaptability to changing threat landscapes deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidadaptability to threats
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts the packet inspection strategy by monitoring factors such as threat intelligence updates, network conditions, and session characteristics. This allows the predefined number of packets to be adapted based on current threats while maintaining relatively simple system architecture through standardized inspection procedures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms that monitor inspection results and threat intelligence to adjust packet selection and inspection depth. This feedback loop enables the system to adapt to changing threat landscapes by learning from inspection outcomes and updating inspection strategies accordingly.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12058152B2Cloud-based implementation of dynamic threat detection
Publication Date: 2024.08.06 CYBER ADAPT INC
  • US12058152B2 patent drawing
  • US12058152B2 patent drawing
  • US12058152B2 patent drawing

AI summary

A dynamic cloud-based threat detection system is disclosed. The system comprises a network broker that receives communication sessions associated with communication device(s) via a network and selects and sends a predefined number of packets of each communication session to a detection based on packet selection rules. The communication device(s) comprises customer premises equipment (CPE) and/or a mobile communication device. The detection engine receives and inspects the predefined number of packets of each communication session and a governor that initiates blocking of particular communication traffic based on the inspection. The system also comprises a dynamic optimizer that monitors factor(s) and creates and sends updated packet rules to the network broker based on the monitoring. The network broker selects and sends a different predefined number of packets of each of a second plurality of communication sessions to the detection engine for inspection based on the updated packet selection rules.