Dynamic Zone Protection Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems based on hardware struggle with computationally complex threat detection and mitigation, especially in high-throughput environments, as they lack efficient and effective processing capabilities to handle dynamic updates and correlate multiple sources for threat detection.

Innovation Solution

A computer-implemented method and system using packet processing engines and processing analysis engines, along with controllers, to dynamically analyze and mitigate threats across a network by distributing processing tasks and updating security measures in real-time, enabling efficient and effective threat detection and mitigation without relying solely on hardware performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based security systems are used for threat detection and mitigation, then device reliability is improved, but processing capability for computationally complex threats deteriorates

Engineering Contradiction:
Improvedevice reliabilityVSAvoidprocessing capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system divides the network into multiple zones with different security requirements and processes packets differently based on their destination zone. Fast-path processing handles routine packets quickly, while deep-path processing performs comprehensive analysis only when needed, segmenting the processing workload to improve overall productivity without sacrificing reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts processing depth and methodology based on real-time conditions, including packet characteristics, network state, and threat intelligence. The controller can reprogram network nodes to change processing behavior on-the-fly, allowing the system to adapt its productivity to match the complexity of threats encountered while maintaining reliable security coverage.

Inventive Principle:
Principle #15Dynamics

2Productivity

If more computing resources are allocated to threat detection, then processing capability is improved, but scalability to high data rates deteriorates

Engineering Contradiction:
Improveprocessing capabilityVSAvoidscalability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system segments processing into fast-path and deep-path modes, allowing most packets to traverse with minimal processing while only suspicious or zone-specific packets receive intensive analysis. This segmentation enables the system to scale to high data rates without requiring proportional increases in computing resources for all packets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The controller provides centralized intelligence that can reprogram multiple network nodes to perform different security functions based on current threats and traffic patterns. This multi-functionality allows the same hardware infrastructure to adapt to varying processing demands, improving scalability while maintaining high processing capability where needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If comprehensive packet analysis is performed for all packets, then measurement precision for threat detection is improved, but processing speed deteriorates

Engineering Contradiction:
Improvethreat detection precisionVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The system dynamically selects between fast-path and deep-path processing based on packet characteristics, destination zone, and current threat intelligence. This dynamic approach ensures comprehensive analysis (high precision) is applied only when necessary, while routine packets receive expedited processing, maintaining both precision and speed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different processing depths are applied to different packets based on their specific characteristics and destination zones. Critical zones receiving enhanced scrutiny while less sensitive zones use standard processing, optimizing the balance between detection precision and processing speed for each local context.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If dynamic reprogramming of network nodes is implemented, then adaptability to new threats is improved, but device complexity deteriorates

Engineering Contradiction:
Improvedynamic adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The controller acts as an intermediary that centralizes the complexity of dynamic reprogramming. Individual network nodes receive simplified reprogramming instructions from the controller rather than implementing complex adaptive logic themselves. This distributes complexity to the controller, which has full visibility and coordination capabilities, reducing the burden on individual nodes while maintaining system-wide adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11283823B1Systems and methods for dynamic zone protection of networks
Publication Date: 2022.03.22 LOOKINGGLASS CYBER SOLUTIONS LLC
  • US11283823B1 patent drawing
  • US11283823B1 patent drawing
  • US11283823B1 patent drawing

AI summary

Disclosed are systems and methods for securing a network using one or more controllers and one or more network nodes. A method may utilize a packet processing engine configured to process incoming network packets, a processing analysis engine configured to perform relatively more complex processing and analysis, and one or more controllers configured to coordinate one or more packet processing engines and one or more processing analysis engines across a network to perform endpoint threat detection and mitigation.