Programmable Policy Engine for Dynamic Wireless Sniffing Traffic Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless intrusion prevention systems (WIPS) face challenges with traffic overhead and resource requirements, making them costly and inaccessible to smaller entities, and there is a need for a dynamic and scalable sniffing sensor system that can adjust to changing network conditions.

Innovation Solution

A system that dynamically adjusts sniffing policies and traffic routing at embedded access points using programmable policy engines, allowing for real-time monitoring and adjustment of sniffed traffic levels to optimize network performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized WIPS solutions are deployed to capture all packets for intrusion detection, then intrusion detection capability is improved, but network bandwidth is consumed by traffic overhead from backhauling packet copies

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements local quality by enabling access points to perform deep packet inspection and intrusion detection locally rather than backhauling all packets to a centralized server. Each access point inspects packets according to configurable policies, allowing intrusion detection to occur at the network edge where traffic is generated, thereby reducing bandwidth consumption while maintaining detection capability

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent extracts the intrusion detection function from the centralized backhaul path and places it at individual access points. By extracting only the necessary inspection capabilities and applying them locally according to policy, the system eliminates the need to backhaul all packet copies, thereby reducing network bandwidth consumption while preserving intrusion detection effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If deep packet inspection is performed at all access points, then intrusion detection accuracy is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidaccess point resource requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamics by making deep packet inspection configurable and policy-driven at each access point. Rather than all access points performing full deep packet inspection simultaneously, the system dynamically enables or disables inspection based on network conditions, traffic types, and security policies. This allows intrusion detection accuracy to be maintained where needed while reducing device complexity and resource consumption at other locations

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies parameter changes by allowing administrators to configure deep packet inspection parameters individually at each access point, including which protocols to inspect, which traffic flows to monitor, and inspection intensity levels. This granular parameter control enables intrusion detection accuracy to be optimized at specific access points without uniformly increasing complexity across the entire network

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all sniffed traffic is backhauled to centralized server for analysis, then detection completeness is improved, but network performance deteriorates due to traffic overhead

Engineering Contradiction:
Improvedetection completenessVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial action by having access points perform deep packet inspection and backhaul only suspicious or anomalous traffic to the centralized server for further analysis. Rather than backhauling all sniffed traffic, the system applies partial filtering and inspection at the edge, backhauling only the portion of traffic that requires centralized attention. This maintains detection completeness for critical threats while significantly reducing network overhead and improving overall network performance

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10944650B2Programmable, policy-based efficient wireless sniffing networks in WIPS (wireless intrusion prevention systems)
Publication Date: 2021.03.09 FORTINET INC
  • US10944650B2 patent drawing
  • US10944650B2 patent drawing
  • US10944650B2 patent drawing

AI summary

A plurality of sniffing policies describing deep packet inspection processes performed on network traffic at sniffing access points from the plurality of access points is received. Network traffic levels are monitored at the plurality of access points and a level of sniffed traffic backhauled over the Wi-Fi network for analysis. A change can be detected in network traffic affecting a sniffing policy. Responsive to exceeding a certain level of sniffed traffic being backhauled, an amount of sniffed traffic sent upstream for analysis is adjusted. More specifically, a programmable policy engine at each of a sniffing access points serving as intrusion detection sensors to sniff traffic at various locations on the Wi-Fi network are reprogrammed dynamically. The adjustments reprogram a sniffing pipeline at each of the intrusion detection sensors including adjusting an endpoint device for sending sniffed traffic and dropping more traffic during deep packet inspection.