Network Packet Buffer Retrieval for Abnormal Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions are inadequate in detecting and preventing advanced persistent threats, as they rely on connected network traffic analysis and lack real-time intelligence, failing to identify sophisticated hacking methods that leave minimal evidence.

Innovation Solution

A computer-implemented method that retrieves and analyzes network packets from a packet buffer using packet location information to identify abnormal application activity, blocks network traffic containing the identified content, and generates rules to prevent further attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security solutions analyze connected network traffic, then they can identify known attacks and malicious behavior, but they fail to detect advanced persistent threats that leave minimal evidence

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect sophisticated attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by buffering network packets and recording their location information before analysis is needed. When abnormal application activity is detected, the buffered packets are already available for immediate retrieval and analysis, eliminating delays associated with real-time capture and enabling faster response to advanced persistent threats

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces packet buffer and packet location information as intermediary components between network traffic and security analysis. These intermediaries store packet data and metadata, allowing security systems to retrieve and analyze packets at their convenience rather than requiring real-time access to live traffic, thus improving detection capabilities for sophisticated attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If network security solutions lack real-time intelligence, then they cannot identify sophisticated hacking methods, but implementing real-time analysis increases system complexity

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by buffering network packets and recording their location information before analysis is needed. When abnormal application activity is detected, the buffered packets are already available for immediate retrieval and analysis, eliminating delays associated with real-time capture and enabling faster response to advanced persistent threats

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts packet location information from the packet buffer and stores it separately in a structured format. This extraction allows the system to efficiently retrieve specific packets for analysis without processing entire network traffic streams, reducing computational complexity while maintaining detection capability

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of information

If existing solutions rely on connected network traffic analysis, then they miss abnormal application activity, but analyzing all traffic increases data processing requirements

Engineering Contradiction:
Improveinformation about abnormal activityVSAvoiddata processing volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent applies local quality by recording packet location information with specific attributes (protocol type, source/destination addresses, ports, sequence numbers) that are relevant to security analysis. This selective recording of locally relevant information allows efficient packet retrieval and analysis without processing entire network traffic streams, reducing data processing volume while preventing information loss about abnormal activity

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10484420B2Retrieving network packets corresponding to detected abnormal application activity
Publication Date: 2019.11.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10484420B2 patent drawing
  • US10484420B2 patent drawing
  • US10484420B2 patent drawing

AI summary

A method for preventing abnormal application activity is provided. Packets are retrieved from a packet buffer using packet location information corresponding to information associated with the abnormal application activity in a data processing system. The packets are analyzed to identify content of the network packets causing the abnormal application activity. Network packets containing the content causing the abnormal application activity in the data processing system are blocked.