Dynamic Packet Inspection Plan System for Resource-Constrained IPS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion Protection Systems (IPS) and Intrusion Detection Systems (IDS) in resource-constrained devices, such as home gateways, are limited in the number of rules they can enforce and packets they can inspect, making it costly to deploy fully functional appliances for large-scale network protection.
Innovation Solution
A method involving a weighted random selection of IPS/IDS rules, where 'basic' and 'probe' rules are dynamically adjusted based on priority and resource availability, allowing for efficient packet inspection plans to be prepared and sent to network distribution devices, optimizing resource usage and adapting to changing security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If fully functional IDS/IPS appliances are deployed to inspect all packets against 40,000 rules, then network security coverage is improved, but deployment cost increases significantly
Solution Approach 1:
The patent segments the 40,000 IPS rules into multiple rule sets that can be dynamically selected and applied to different packets. Instead of requiring a single appliance to handle all rules simultaneously, the system divides the rule base into manageable portions that are inspected sequentially, allowing cost-constrained devices to achieve comprehensive security coverage over time without the full deployment cost of a fully functional appliance.
Solution Approach 2:
The patent implements dynamic rule selection where the inspection plan adapts based on packet characteristics, rule priorities, and resource availability. The system dynamically determines which rules to apply to which packets, enabling cost-constrained devices to achieve security coverage comparable to expensive appliances by intelligently allocating inspection resources across the full rule set over multiple inspection cycles.
2Reliability
If resource-constrained devices enforce more IPS rules, then security coverage is improved, but device performance deteriorates due to limited CPU and memory resources
Solution Approach 1:
The patent segments packet inspection into phases where different rule sets are applied to different packet portions or at different inspection depths. This allows resource-constrained devices to maintain comprehensive security coverage by dividing the inspection workload across multiple manageable segments rather than requiring all rules to be applied simultaneously to every packet.
Solution Approach 2:
The patent applies partial inspection action by selectively applying rules based on packet characteristics and priority levels. Not all rules are applied to all packets, but rather a strategically selected subset is applied to achieve adequate security coverage with minimal resource consumption, accepting that some packets may not undergo full inspection while maintaining overall security effectiveness.
3Device complexity
If static rule sets are used in resource-constrained devices, then implementation simplicity is maintained, but adaptability to changing security risks is reduced
Solution Approach 1:
The patent implements dynamic rule selection where the inspection plan adapts based on packet characteristics, rule priorities, and resource availability. The system dynamically determines which rules to apply to which packets, enabling cost-constrained devices to achieve security coverage comparable to expensive appliances by intelligently allocating inspection resources across the full rule set.
Solution Approach 2:
The patent incorporates feedback mechanisms where inspection results and security event data are used to refine future rule selection and prioritization. This feedback loop enables the system to learn from past inspections and adjust its rule application strategy, improving adaptability to emerging threats while maintaining relatively simple implementation through automated decision-making.
Data Source
AI summary
In one example, a method includes for each one time period of a plurality of time periods performing a weighted random selection of a first set of intrusion detection/protection system rules from a plurality of rules, each rule of the plurality of rules having an associated probability of selection, preparing a packet inspection plan including the first set of intrusion detection/protection system rules, and sending the packet inspection plan to a network distribution device to inspect packets according to the packet inspection plan. Related apparatus and methods are also described.


