Hybrid CPE Cloud Threat Detection via Packet Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home networks are increasingly vulnerable to cyber-attacks due to the growing number of devices and lack of basic cybersecurity measures, with existing threat detection solutions relying on reputation-based methods that are ineffective against constantly changing threats and resource-intensive deep packet inspection being impractical for residential environments.

Innovation Solution

A dynamic hybrid residential threat detection system that uses packet inspection on customer premises equipment (CPE) and in the cloud, optimizing resource usage by selecting a predefined number of packets for inspection based on resource constraints, threat levels, and communication session characteristics, with CPE detection rules being a subset of cloud detection rules and dynamically adjusting inspection levels and packet selection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is performed on all packets, then threat detection accuracy is improved, but resource consumption increases making it impractical for residential environments

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The packet inspection process is segmented into two distinct phases: a first level of inspection performed by the CPE detection engine using CPE detection rules, and a second level of inspection performed by the cloud detection engine using cloud detection rules. This segmentation allows the system to perform basic threat detection locally with minimal resources while sending only selected packets to the cloud for more thorough analysis, thus resolving the contradiction between detection accuracy and resource consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of inspecting all packets (excessive action), the system performs partial inspection by selecting only a predefined number of packets from each communication session for the first level of inspection at the CPE, and potentially only some of those for the second level at the cloud. This partial action approach maintains sufficient threat detection capability while significantly reducing the resource burden on residential devices.

Inventive Principle:
Principle #16Partial or excessive action

2Speed

If packet inspection is performed at the CPE, then local threat detection speed is improved, but CPE resource constraints limit the inspection depth

Engineering Contradiction:
Improvelocal threat detection speedVSAvoidCPE resource constraints
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The inspection workload is segmented between the CPE and the cloud. The CPE performs the first level of inspection using CPE detection rules, which are designed to be lightweight and executable within local resource constraints. Packets that pass this initial filter are then sent to the cloud for the second level of inspection. This segmentation enables fast local detection of common threats while deferring resource-intensive analysis to the cloud.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different inspection qualities at different locations: the CPE uses simplified CPE detection rules optimized for local execution with limited resources, while the cloud uses more comprehensive cloud detection rules that can perform deeper analysis. This local quality differentiation allows the CPE to operate within its resource constraints while still contributing to overall threat detection effectiveness.

Inventive Principle:
Principle #3Local quality

3Reliability

If all communication sessions are inspected, then threat detection coverage is improved, but network performance impact increases

Engineering Contradiction:
Improvethreat detection coverageVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The inspection process is segmented into two stages: first, the CPE performs a preliminary inspection of a predefined number of packets from each communication session using CPE detection rules. Only packets that are selected in this first stage are forwarded to the cloud for second-level inspection. This segmentation maintains broad threat detection coverage across all communication sessions while minimizing the impact on network performance by avoiding simultaneous deep inspection of all sessions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial inspection by limiting the number of packets inspected from each communication session to a predefined number, rather than inspecting all packets. This partial action approach ensures that threat detection coverage is maintained for the most critical packets while leaving sufficient bandwidth and processing capacity available for normal network traffic, thus preserving network performance.

Inventive Principle:
Principle #16Partial or excessive action

4Speed

If CPE detection rules are used, then inspection speed is improved, but detection capability is limited compared to cloud-based rules

Engineering Contradiction:
Improveinspection speedVSAvoiddetection capability
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The detection rules are segmented into two sets: CPE detection rules that are simplified and optimized for fast local execution, and cloud detection rules that are more comprehensive but resource-intensive. The CPE applies the faster CPE detection rules to the first level of inspection, achieving high inspection speed. For packets that require more sophisticated analysis, the system sends them to the cloud which applies the more capable cloud detection rules, thus achieving enhanced detection capability for complex threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses partial detection capability at the CPE level by applying simplified CPE detection rules that provide sufficient protection for common threats while maintaining fast inspection speed. The more sophisticated cloud detection rules are applied only partially to selected packets that may contain advanced or elusive threats, thus achieving enhanced detection capability where needed without compromising the overall speed of inspection for the majority of traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240333727A1Hybrid customer premises equipment and cloud-based implementation of dynamic residential threat detection
Publication Date: 2024.10.03 CYBER ADAPT INC
  • US20240333727A1 patent drawing
  • US20240333727A1 patent drawing
  • US20240333727A1 patent drawing

AI summary

A dynamic hybrid residential threat detection method is disclosed. The method includes receiving, by a packet selector on a customer premises equipment (CPE), communication sessions and selecting and sending, by the packet selector, a predefined number of packets of the communication sessions to a CPE detection engine based on packet selection rules. The method also includes inspecting, by the CPE detection engine, the predefined number of packets of each communication session based on CPE detection rules that establish what type of inspection is to be performed by the CPE detection engine based at least in part on CPE resource constraints. The method further includes sending, by the packet selector, the predefined number of packets of at least some of the communication sessions to a cloud detection engine and blocking particular communication traffic on the CPE based on the inspection and/or an instruction from the cloud detection engine.