Inline Rule Inspection Using Probabilistic Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional rule-based network security systems face performance and scalability challenges in detecting sophisticated cyber threats due to the extensive resource-intensive nature of traffic inspection, leading to delays and bottlenecks.
Innovation Solution
Implement probability-based inline rule inspection using concurrent evaluation and adaptive load balancing, where rules are assigned probabilities based on execution time and historical effectiveness, enabling parallel processing and selective rule application to optimize traffic inspection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional rule-based traffic inspection is performed on all network traffic, then security detection capability is improved, but system performance and processing speed deteriorate due to resource-intensive operations
Solution Approach 1:
The patent applies partial action by selectively inspecting only a subset of network traffic using probability-based rule application. Instead of applying all security rules to every packet, the system determines which rules to apply based on probability thresholds and traffic characteristics, achieving adequate security coverage while reducing processing overhead and improving throughput
Solution Approach 2:
The system dynamically changes the parameter of rule application probability based on traffic conditions, rule importance, and system load. By adjusting the probability threshold for rule application, the system can adapt between security-focused mode (higher probability) and performance-focused mode (lower probability), resolving the contradiction between detection capability and processing speed
2Measurement precision
If comprehensive traffic inspection rules are applied to detect sophisticated cyber threats, then measurement precision of threats is improved, but computation expense and latency increase
Solution Approach 1:
The system performs preliminary classification of traffic into risk categories before applying detailed inspection rules. By pre-assessing traffic based on basic characteristics and applying different probability thresholds for different traffic types, the system prepares the inspection process in advance, reducing actual inspection latency while maintaining detection accuracy for suspicious traffic
Solution Approach 2:
The patent segments the rule inspection process into multiple stages with different probability thresholds. High-probability rules are applied to all traffic, while low-probability comprehensive rules are applied only to flagged traffic segments, achieving thorough detection where needed while minimizing overall inspection time
3Productivity
If multiple security rules are inspected concurrently for each payload, then productivity of traffic inspection is improved, but device complexity increases
Solution Approach 1:
The system implements dynamic rule selection where the set of concurrently inspected rules changes based on traffic characteristics, system state, and probability thresholds. This dynamic approach allows the system to optimize throughput by adjusting the number and type of concurrent rules without requiring a permanently complex processing architecture for all possible scenarios
Data Source
AI summary
Systems and methods for probability-based inline rule inspection include performing inline monitoring between one or more endpoints and the internet; receiving a payload based on the inline monitoring; and performing traffic inspection of the payload based on one or more rules, wherein each of the one or more rules are inspected based on a probability assigned thereto, and wherein the probability assigned to each of the one or more rules can be a function of an execution time of each of the one or more rules and a historic effectiveness of each of the one or more rules.


