Hybrid CPE Cloud Threat Detection via Packet Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home networks are increasingly vulnerable to cyber-attacks due to the growing number of devices and lack of basic cybersecurity measures, with existing threat detection solutions being ineffective in identifying malicious traffic, especially from new or changing sources, and facing resource constraints that hinder deep packet inspection.

Innovation Solution

A dynamic hybrid residential threat detection system that combines local and cloud-based packet inspection, using customer premises equipment (CPE) and cloud detection engines to apply detection rules based on resource constraints, optimizing packet selection and inspection levels to manage bandwidth and processing demands, allowing for efficient detection and blocking of malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is performed to improve threat detection accuracy, then measurement precision is improved, but use of energy and processing resources worsen due to CPE resource constraints

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidCPE processing resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system segments packet inspection into two levels: a first level performed by the CPE detection engine using a subset of detection rules, and a second level performed by the cloud-based detection engine using the complete set of detection rules. This segmentation allows the CPE to perform basic filtering with limited resources while the cloud handles comprehensive analysis, resolving the contradiction between detection accuracy and resource consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The CPE detection engine performs partial inspection by applying only a subset of detection rules to packets, rather than executing the complete set of cloud-based rules. This partial action enables the CPE to operate within its resource constraints while still providing meaningful threat detection, with the cloud engine performing the remaining analysis on selected packets.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If cloud-based detection rules are applied to improve threat detection, then reliability is improved, but loss of time occurs due to network transmission delays

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidpacket inspection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The CPE detection engine performs preliminary packet inspection and filtering using a subset of detection rules before forwarding packets to the cloud. This preliminary action enables the system to quickly eliminate obvious threats and filter traffic locally, reducing the time packets spend in transit and minimizing delays while maintaining reliable detection through subsequent cloud-based analysis.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If packet selection is increased to improve detection coverage, then measurement precision is improved, but productivity decreases due to increased processing load

Engineering Contradiction:
Improvedetection coverageVSAvoidnetwork throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies partial inspection by having the CPE evaluate packets against a subset of detection rules and forward only selected packets to the cloud for complete analysis. This approach maintains comprehensive detection coverage for critical threats while limiting the overall processing load on the CPE, thereby preserving network throughput and productivity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12063232B2Hybrid customer premises equipment and cloud-based implementation of dynamic residential threat detection
Publication Date: 2024.08.13 CYBER ADAPT INC
  • US12063232B2 patent drawing
  • US12063232B2 patent drawing
  • US12063232B2 patent drawing

AI summary

A dynamic hybrid residential threat detection method is disclosed. The method includes receiving, by a packet selector on a customer premises equipment (CPE), communication sessions and selecting and sending, by the packet selector, a predefined number of packets of the communication sessions to a CPE detection engine based on packet selection rules. The method also includes inspecting, by the CPE detection engine, the predefined number of packets of each communication session based on CPE detection rules that establish what type of inspection is to be performed by the CPE detection engine based at least in part on CPE resource constraints. The method further includes sending, by the packet selector, the predefined number of packets of at least some of the communication sessions to a cloud detection engine and blocking particular communication traffic on the CPE based on the inspection and/or an instruction from the cloud detection engine.