Dynamic Packet Selection for Residential Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home networks are increasingly vulnerable to cyber-attacks due to the growing number of devices and lack of basic cybersecurity measures, with existing residential threat detection solutions being ineffective in identifying new or changing threats and requiring extensive resources, making them impractical for residential environments.

Innovation Solution

A dynamically optimized packet inspection method is implemented in customer premises equipment (CPE) that monitors CPE load characteristics, internal and external threat information, and asset characteristics to create packet selection rules, allowing for the efficient inspection of a predefined number of packets from communication sessions, thereby identifying potential threats and blocking malicious traffic without disrupting network performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive packet inspection is performed on all communication sessions, then threat detection accuracy is improved, but network performance deteriorates and resource consumption increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system inspects only a predefined number of packets from each communication session rather than performing comprehensive inspection on all packets. This partial action approach maintains adequate threat detection while significantly reducing the processing burden on network resources and maintaining network performance.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The packet inspection process is segmented by dividing communication sessions into individual packet units, where only a limited number of packets per session are selected for inspection. This segmentation allows the system to manage inspection workload efficiently while maintaining security effectiveness.

Inventive Principle:
Principle #1Segmentation

2Reliability

If packet inspection resources are increased to detect more threats, then threat detection capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidresource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of allocating resources to inspect all packets, the system inspects only a predefined subset of packets from each session. This reduces the computational resources, memory, and processing power required for threat detection, making the solution feasible for residential CPE devices with limited capabilities.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If all packets from communication sessions are inspected, then detection precision is improved, but loss of time and processing overhead increase

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system achieves adequate detection precision by inspecting only a predefined number of packets from each communication session rather than all packets. This partial inspection approach maintains the ability to detect threats while significantly reducing processing time and minimizing impact on network throughput.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12039043B2Customer premises equipment implementation of dynamic residential threat detection
Publication Date: 2024.07.16 CYBER ADAPT INC
  • US12039043B2 patent drawing
  • US12039043B2 patent drawing
  • US12039043B2 patent drawing

AI summary

A method of dynamic residential threat detection is disclosed. The method includes a packet selection component on a customer premises equipment (CPE) sending a predefined number of packets of each of a plurality of communication sessions to a detection engine based on packet selection rules. The method also includes the detection engine on the CPE receiving and inspecting the predefined number of packets. The method further includes a dynamic optimizing component on the CPE monitoring one or more factors and creating and sending updated packet selection rules based on the monitored factor(s) to the packet selection component. The method additionally comprises the packet selection component sending a different predefined number of packets of each of a second plurality of communication sessions to the detection engine based on the updated packet selection rules. The method further includes the detection engine receiving and inspecting the different predefined number of packets.