Edge Network Traffic Analysis with Dynamic Sampling Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprise communication networks face challenges in analyzing vast amounts of network data traffic while ensuring real-time communication integrity, as delays in security analysis can disrupt audio and video synchronization and user experience.

Innovation Solution

Implementing an edge system that processes a first portion of data packets to assess the risk and adjust the sampling policy, identifying a second portion for real-time security workflow analysis, and reordering processes within the workflow to prioritize unsecure packet detection, ensuring that only necessary packets are analyzed in real-time to avoid disrupting communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all data packets are analyzed for security threats, then security assessment accuracy is improved, but real-time communication delay increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidreal-time communication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments data packets into two categories: real-time communication packets (voice/video) and non-real-time packets. Different analysis strategies are applied to each segment, with real-time packets receiving expedited processing or selective analysis to minimize delay while maintaining security assessment accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of analyzing every packet equally, the system applies partial action by performing full security analysis only on suspicious or non-real-time packets, while using lighter-weight inspection methods for routine real-time traffic, thereby reducing overall processing delay while maintaining adequate security coverage.

Inventive Principle:
Principle #16Partial or excessive action

2Measurement precision

If sampling rate is increased to improve risk assessment, then security detection capability is improved, but processing resource consumption increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidprocessing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The sampling rate is made dynamic rather than static. The system adjusts the sampling rate based on current network conditions, threat levels, and traffic patterns. When threats are detected or risk levels rise, the sampling rate increases automatically; during normal conditions, it decreases to conserve processing resources.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where analysis results from sampled packets feed back into adjusting future sampling rates. When high-value threats are detected in the sample, the system increases sampling intensity; when the sample shows low risk, sampling intensity is reduced, creating an adaptive resource allocation system.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9935968B2Selective traffic analysis at a communication network edge
Publication Date: 2018.04.03 PULSELINK SYSTEMS LLC
  • US9935968B2 patent drawing
  • US9935968B2 patent drawing
  • US9935968B2 patent drawing

AI summary

Embodiments disclosed herein provide systems and methods for recording for analyzing traffic at an edge of a communication network. In a particular embodiment, a method provides processing a first portion of data packets directed into the communication network from outside of the communication network to determine whether a first sampling policy adequately assesses risk to the communication network. Upon determining that the first sampling policy does not adequately assess the risk to the communication network, the method provides adjusting the first sampling policy. The method further provides identifying a second portion of the data packets based on the first sampling policy. An amount of data packets included in the first portion of the data packets is larger than or equal to an amount of data packets included in the second portion of the data packets.