Endpoint cSensors for Intelligent DPI and Network Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber security systems are inadequate in protecting against complex modern threats, particularly insider threats and IoT devices, due to limited network visibility and specialized machine learning approaches that fail to analyze uncommon data types and protocols.

Innovation Solution

Implementing endpoint agent client sensors (cSensors) that monitor network traffic, perform intelligent deep packet inspection, and extend network visibility by integrating with operating systems to analyze and transmit data to a cyber security appliance, while performing autonomous actions when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls and endpoint security tools are deployed, then basic policy enforcement and protection are provided, but they are insufficient against complex modern threats such as insider threats

Engineering Contradiction:
Improveprotection capabilityVSAvoidthreat coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the network into multiple logical zones (office network, email environment, production environment, IoT devices, remote systems) and deploys specialized security measures in each zone. This allows different security policies and analysis approaches to be applied to different threat vectors, improving both reliability and adaptability against diverse threats including insider threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cyber protection system is designed to accommodate multiple data types and protocols across different network zones through a universal machine learning platform. The system can analyze traditional enterprise data as well as uncommon data types from IoT devices and smart systems, providing versatile threat detection across all zones without requiring separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If commercial cyber threat defense systems are restricted to logical enterprise zones with specialized machine learning approaches, then focused analysis is achieved, but they cannot accommodate unseen data types and structures without significant development work

Engineering Contradiction:
Improveanalysis accuracyVSAvoiddata type compatibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The machine learning platform is designed with universal data processing capabilities that can handle multiple data types and protocols simultaneously. The system ingests data from various sources including traditional enterprise systems and IoT devices with uncommon protocols, applying appropriate analysis methods to each data type while maintaining a unified security posture across all zones.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adapts its analysis approach based on the data type and source. The machine learning models can adjust their parameters and methods to optimize analysis accuracy for different data structures, whether they are standard enterprise data or unconventional IoT data, without requiring significant reconfiguration or development work.

Inventive Principle:
Principle #15Dynamics

3Loss of information

If lower level protocols in the protocol stack are analyzed, then comprehensive network visibility is achieved, but the data types differ from those typically analyzed by traditional cyber security protection systems

Engineering Contradiction:
Improvenetwork visibilityVSAvoidprotocol analysis complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments protocol analysis by layer, with different machine learning models specialized for analyzing data at various levels of the protocol stack. Lower level protocols are analyzed using models trained on their specific data types, while higher level protocols use different specialized models, allowing comprehensive visibility without overwhelming complexity in a single analysis engine.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12463985B2Endpoint agent client sensors (cSENSORS) and associated infrastructures for extending network visibility in an artificial intelligence (AI) threat defense environment
Publication Date: 2025.11.04 DARKTRACE HLDG LTD
  • US12463985B2 patent drawing
  • US12463985B2 patent drawing
  • US12463985B2 patent drawing

AI summary

Endpoint agent cSensors can be used to extend network visibility and enhance tracking capabilities for a cyber security and threat defense environment. The cSensor may comprise a network module to monitor network information coming into and out of the endpoint computing device to ingest a first set of traffic data from network connections. The cSensor may have a collation module to collect the first set of traffic data and obtain input data related to observed network events. An analyzer module can receive the input data and use an intelligent DPI engine to perform predetermined levels of DPI from two or more possible levels of DPI on the input data based on network parameters. The cSensor may have a communication module to transmit a second set of traffic data to a cyber security appliance based on the specified DPI performed. Furthermore, the cSensor may have an autonomous action module to perform autonomous action(s) in response to autonomous action(s) correlated to the received second set of traffic data.