Packet Capture Filtering with Aggregated Threat Indicators
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional packet capture solutions for cyber threat analysis are inefficient and expensive, capturing a large volume of non-threat packets, leading to low fidelity of threat incidents and high operational costs, with conventional systems taking weeks or months to discover network attacks due to the inability to discriminate between threat and legitimate packets.
Innovation Solution
A purpose-built packet filter that aggregates threat indicators from multiple providers, filters and captures packets based on these indicators at the network boundary, and integrates threat filtering, logging, and capture to efficiently detect threat incidents, including bidirectional flows and threat context information in packet capture files.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional packet capture solutions capture all or substantially all packets to ensure threat incident packets are stored, then completeness of threat packet capture is improved, but storage cost and processing overhead increase by 10×-100×
Solution Approach 1:
The system performs preliminary classification of packets using threat indicators and machine learning models before capture decisions are made. This preliminary action identifies threat-related packets in advance, allowing the system to capture only necessary packets while avoiding the need to store all packets.
Solution Approach 2:
The system extracts and captures only the specific threat-related packets from the overall network traffic stream, separating them from legitimate traffic. This extraction approach captures only the necessary subset of packets that contain threat information, eliminating the need to store all packets.
2Reliability
If conventional systems log all packet transit events to detect threat incidents, then threat detection capability is improved, but operational cost and resource consumption increase by 10×-100×
Solution Approach 1:
The system performs preliminary analysis using threat indicators and machine learning models to identify packets that require logging. This preliminary action filters out legitimate traffic before it reaches the logging stage, significantly reducing the volume of data that needs to be stored and processed while maintaining threat detection capability.
Solution Approach 2:
The system extracts only the threat-related packet events from the overall traffic stream for logging and analysis. By separating threat events from legitimate events at an early stage, the system reduces logging costs by 10×-100× while maintaining the ability to detect threat incidents.
3Measurement precision
If conventional packet filtering devices search logs for each threat indicator separately, then thorough threat analysis is improved, but time to discover attacks increases to weeks or months
Solution Approach 1:
The system merges multiple threat indicator searches into a unified, parallel processing architecture. Instead of sequentially searching for each indicator, the system combines multiple indicators and searches them simultaneously using distributed computing resources, reducing discovery time from weeks or months to minutes or seconds while maintaining thorough analysis.
Solution Approach 2:
The system implements dynamic, adaptive searching that adjusts search parameters and resource allocation based on the specific threat indicators and network traffic patterns. This dynamic approach optimizes the balance between thoroughness and speed, allowing the system to maintain comprehensive threat analysis while dramatically reducing discovery time through intelligent resource management.
4Productivity
If conventional systems capture bidirectional flows only when most packets match indicator rules, then capture efficiency is improved, but completeness of threat analysis is reduced
Solution Approach 1:
The system performs preliminary classification of bidirectional flows using threat indicators and machine learning models to identify flows that contain threat activity. This preliminary action enables the system to capture complete bidirectional flows when threats are detected, while avoiding unnecessary capture of legitimate flows, thus maintaining both efficiency and completeness.
Solution Approach 2:
The system extracts and captures complete bidirectional flows only when threat indicators or machine learning models identify threat activity in either direction. This extraction approach ensures that when threats are present, the complete contextual information from both directions is captured for thorough analysis, while avoiding waste on legitimate traffic.
Data Source
AI summary
Methods, systems, and computer-readable media for efficiently detecting threat incidents for cyber threat analysis are described herein. In various embodiments, a computing device, which may be located at a boundary between a protected network associated with the enterprise and an unprotected network, may combine one or more threat indicators received from one or more threat intelligence providers; may generate one or more packet capture and packet filtering rules based on the combined threat indicators; and, may capture or filter, on a packet-by-packet basis, at least one packet based on the generated rules. In other embodiments, a computing device may generate a packet capture file comprising raw packet content and corresponding threat context information, wherein the threat context information may comprise a filtering rule and an associated threat indicator that caused the packet to be captured.


