Packet Capture Filters with Dynamic Modes and Intervals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for identifying and mitigating attacks from compromised computers are ineffective, slow, or incomplete, especially when attackers are behind firewalls or malicious state actors, making it difficult to trace the ultimate attacker and detect malware usage.

Innovation Solution

A distributed network of sensor computers captures data packets using packet capture filters managed by a command server, allowing for the identification and collection of malicious data packets from compromised computers, even when attackers are hidden behind firewalls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packet capture filters are applied to all sensor computers continuously, then complete attack detection is achieved, but system resource consumption and data volume increase significantly

Engineering Contradiction:
Improveattack detection completenessVSAvoidsystem resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements periodic packet capture by alternating between capture modes (surveillance, investigation, evidence collection) based on threat levels and time intervals. Sensors periodically switch between active packet capture and idle states, reducing resource consumption while maintaining detection capability through scheduled surveillance periods.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system dynamically adjusts packet capture intensity and duration based on real-time threat assessments, incident severity levels, and sensor workload. Capture filters are activated or deactivated dynamically in response to changing security conditions, optimizing resource usage while maintaining detection effectiveness.

Inventive Principle:
Principle #15Dynamics

2Loss of information

If packet capture filters are applied continuously to all sensors, then all malicious packets are captured, but storage requirements and data processing complexity increase

Engineering Contradiction:
Improvemalicious packet capture completenessVSAvoidcaptured data volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent extracts and captures only specific packet characteristics and metadata relevant to security threats rather than capturing complete packet streams. The system extracts essential information (source/destination addresses, ports, protocols, threat indicators) while filtering out redundant data, reducing storage requirements while maintaining analysis capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Different sensors apply different capture filter configurations based on their local network positions, threat profiles, and assigned surveillance targets. Each sensor captures data with quality and detail appropriate to its specific function and threat level, avoiding uniform over-capture across all sensors.

Inventive Principle:
Principle #3Local quality

3Speed

If packet capture is performed without time intervals, then immediate attack detection is possible, but false positives and noise increase

Engineering Contradiction:
Improveattack detection speedVSAvoidattack detection accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The system performs preliminary packet capture in surveillance mode before full investigation mode, allowing initial threat identification and baseline establishment. This preliminary action enables the system to distinguish between normal and anomalous traffic patterns, reducing false positives while maintaining rapid detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback loops where captured packet data is analyzed, and results inform subsequent capture decisions. Detection accuracy is continuously improved by feeding analysis results back into filter configuration adjustments, allowing the system to refine its detection precision while maintaining speed through learned patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10574669B1Packet filters in security appliances with modes and intervals
Publication Date: 2020.02.25 CLOUDFLARE INC
  • US10574669B1 patent drawing
  • US10574669B1 patent drawing
  • US10574669B1 patent drawing

AI summary

A computer system programmed to provide improved packet capture comprises: a plurality of sensor computers each programmed to capture data packets directed to a different compromised computer; a command server that is programmed to determine an expiration time for capturing a first set of data packets that have been routed toward a first compromised computer, to determine a time interval indicating an interval for capturing the first set of data packets, to identify a first packet capture filter of a plurality of packet capture filters for a first sensor computer of the plurality of sensor computers, to transmit, via a communications network, the first packet capture filter and a message, which comprises the time interval and the expiration time, to the first sensor computer of the plurality of sensor computers to capture the first set of data packets every the time interval and until the expiration time expires.