Dynamic Packet Inspection Plan System for Resource-Constrained IPS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion Protection Systems (IPS) and Intrusion Detection Systems (IDS) in resource-constrained devices, such as home gateways, are limited in the number of rules they can enforce and packets they can inspect, making it costly to deploy fully functional appliances for large-scale network protection.

Innovation Solution

A method involving a weighted random selection of IPS/IDS rules, where 'basic' and 'probe' rules are dynamically adjusted based on priority and resource availability, allowing for efficient packet inspection plans to be prepared and sent to network distribution devices, optimizing resource usage and adapting to changing security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fully functional IDS/IPS appliances are deployed to inspect all packets against 40,000 rules, then network security coverage is improved, but deployment cost increases significantly

Engineering Contradiction:
Improvenetwork security coverageVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the 40,000 IPS rules into multiple rule sets that can be dynamically selected and applied to different packets. Instead of requiring a single appliance to handle all rules simultaneously, the system divides the rule base into manageable portions that are inspected sequentially, allowing cost-constrained devices to achieve comprehensive security coverage over time without the full deployment cost of a fully functional appliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic rule selection where the inspection plan adapts based on packet characteristics, rule priorities, and resource availability. The system dynamically determines which rules to apply to which packets, enabling cost-constrained devices to achieve security coverage comparable to expensive appliances by intelligently allocating inspection resources across the full rule set over multiple inspection cycles.

Inventive Principle:
Principle #15Dynamics

2Reliability

If resource-constrained devices enforce more IPS rules, then security coverage is improved, but device performance deteriorates due to limited CPU and memory resources

Engineering Contradiction:
Improvesecurity coverageVSAvoidpacket inspection throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments packet inspection into phases where different rule sets are applied to different packet portions or at different inspection depths. This allows resource-constrained devices to maintain comprehensive security coverage by dividing the inspection workload across multiple manageable segments rather than requiring all rules to be applied simultaneously to every packet.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial inspection action by selectively applying rules based on packet characteristics and priority levels. Not all rules are applied to all packets, but rather a strategically selected subset is applied to achieve adequate security coverage with minimal resource consumption, accepting that some packets may not undergo full inspection while maintaining overall security effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If static rule sets are used in resource-constrained devices, then implementation simplicity is maintained, but adaptability to changing security risks is reduced

Engineering Contradiction:
Improveimplementation simplicityVSAvoidadaptability to changing security risks
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic rule selection where the inspection plan adapts based on packet characteristics, rule priorities, and resource availability. The system dynamically determines which rules to apply to which packets, enabling cost-constrained devices to achieve security coverage comparable to expensive appliances by intelligently allocating inspection resources across the full rule set.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where inspection results and security event data are used to refine future rule selection and prioritization. This feedback loop enables the system to learn from past inspections and adjust its rule application strategy, improving adaptability to emerging threats while maintaining relatively simple implementation through automated decision-making.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10785234B2Dynamic packet inspection plan system utilizing rule probability based selection
Publication Date: 2020.09.22 CISCO TECHNOLOGY INC
  • US10785234B2 patent drawing
  • US10785234B2 patent drawing
  • US10785234B2 patent drawing

AI summary

In one example, a method includes for each one time period of a plurality of time periods performing a weighted random selection of a first set of intrusion detection/protection system rules from a plurality of rules, each rule of the plurality of rules having an associated probability of selection, preparing a packet inspection plan including the first set of intrusion detection/protection system rules, and sending the packet inspection plan to a network distribution device to inspect packets according to the packet inspection plan. Related apparatus and methods are also described.