Packet Capture Filtering with Aggregated Threat Indicators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional packet capture solutions for cyber threat analysis are inefficient and expensive, capturing a large volume of non-threat packets, leading to low fidelity of threat incidents and high operational costs, with conventional systems taking weeks or months to discover network attacks due to the inability to discriminate between threat and legitimate packets.

Innovation Solution

A purpose-built packet filter that aggregates threat indicators from multiple providers, filters and captures packets based on these indicators at the network boundary, and integrates threat filtering, logging, and capture to efficiently detect threat incidents, including bidirectional flows and threat context information in packet capture files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional packet capture solutions capture all or substantially all packets to ensure threat incident packets are stored, then completeness of threat packet capture is improved, but storage cost and processing overhead increase by 10×-100×

Engineering Contradiction:
Improvecompleteness of threat packet captureVSAvoidnumber of packets stored
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system performs preliminary classification of packets using threat indicators and machine learning models before capture decisions are made. This preliminary action identifies threat-related packets in advance, allowing the system to capture only necessary packets while avoiding the need to store all packets.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts and captures only the specific threat-related packets from the overall network traffic stream, separating them from legitimate traffic. This extraction approach captures only the necessary subset of packets that contain threat information, eliminating the need to store all packets.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If conventional systems log all packet transit events to detect threat incidents, then threat detection capability is improved, but operational cost and resource consumption increase by 10×-100×

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary analysis using threat indicators and machine learning models to identify packets that require logging. This preliminary action filters out legitimate traffic before it reaches the logging stage, significantly reducing the volume of data that needs to be stored and processed while maintaining threat detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts only the threat-related packet events from the overall traffic stream for logging and analysis. By separating threat events from legitimate events at an early stage, the system reduces logging costs by 10×-100× while maintaining the ability to detect threat incidents.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If conventional packet filtering devices search logs for each threat indicator separately, then thorough threat analysis is improved, but time to discover attacks increases to weeks or months

Engineering Contradiction:
Improvethoroughness of threat analysisVSAvoidtime to discover attacks
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system merges multiple threat indicator searches into a unified, parallel processing architecture. Instead of sequentially searching for each indicator, the system combines multiple indicators and searches them simultaneously using distributed computing resources, reducing discovery time from weeks or months to minutes or seconds while maintaining thorough analysis.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements dynamic, adaptive searching that adjusts search parameters and resource allocation based on the specific threat indicators and network traffic patterns. This dynamic approach optimizes the balance between thoroughness and speed, allowing the system to maintain comprehensive threat analysis while dramatically reducing discovery time through intelligent resource management.

Inventive Principle:
Principle #15Dynamics

4Productivity

If conventional systems capture bidirectional flows only when most packets match indicator rules, then capture efficiency is improved, but completeness of threat analysis is reduced

Engineering Contradiction:
Improvecapture efficiencyVSAvoidcompleteness of threat analysis
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary classification of bidirectional flows using threat indicators and machine learning models to identify flows that contain threat activity. This preliminary action enables the system to capture complete bidirectional flows when threats are detected, while avoiding unnecessary capture of legitimate flows, thus maintaining both efficiency and completeness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts and captures complete bidirectional flows only when threat indicators or machine learning models identify threat activity in either direction. This extraction approach ensures that when threats are present, the complete contextual information from both directions is captured for thorough analysis, while avoiding waste on legitimate traffic.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12375447B2Efficient packet capture for cyber threat analysis
Publication Date: 2025.07.29 CENTRIPETAL NETWORKS INC
  • US12375447B2 patent drawing
  • US12375447B2 patent drawing
  • US12375447B2 patent drawing

AI summary

Methods, systems, and computer-readable media for efficiently detecting threat incidents for cyber threat analysis are described herein. In various embodiments, a computing device, which may be located at a boundary between a protected network associated with the enterprise and an unprotected network, may combine one or more threat indicators received from one or more threat intelligence providers; may generate one or more packet capture and packet filtering rules based on the combined threat indicators; and, may capture or filter, on a packet-by-packet basis, at least one packet based on the generated rules. In other embodiments, a computing device may generate a packet capture file comprising raw packet content and corresponding threat context information, wherein the threat context information may comprise a filtering rule and an associated threat indicator that caused the packet to be captured.