Threat-Aware Packet Filtering With Real-Time Disposition Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing packet-filtering appliances struggle with deterministic disposition determination for threat indicator rules due to uncertain, subjective, or probabilistic threat risks, leading to potential false positives or negatives in network protection.

Innovation Solution

Implementing a 'protect' disposition for threat indicator rules that allows real-time computation of dispositions and directives based on observed threat context information, including local and global threat context, to dynamically determine the best action for in-transit packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packet filtering rules are configured with predetermined dispositions based on threat indicators, then network protection is provided, but false positives or negatives occur due to uncertain threat risks

Engineering Contradiction:
Improvenetwork protection accuracyVSAvoidthreat risk determination accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies dynamics by transitioning from static predetermined dispositions to dynamic real-time disposition determination. The system dynamically evaluates threat context information (such as packet flow patterns, temporal characteristics, and spatial relationships) at the moment of packet observation, allowing the disposition to adapt based on current threat conditions rather than relying on fixed pre-configured rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback by using observed threat context information from actual packet traffic to inform disposition decisions. The system continuously monitors packet flows, evaluates contextual threat indicators, and uses this feedback to determine appropriate dispositions in real-time, creating a closed-loop system that adapts to actual observed threats rather than relying solely on predetermined rules.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If real-time computation of dispositions is performed based on observed threat context, then accurate packet filtering is achieved, but processing latency increases

Engineering Contradiction:
Improvedisposition determination accuracyVSAvoidpacket processing latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring packet filtering rules with associated threat context parameters and disposition options before packets arrive. The system prepares evaluation criteria and threat context frameworks in advance, so that when packets are observed, the real-time computation can efficiently query pre-prepared data structures and apply pre-defined evaluation logic, reducing actual processing latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the essential threat context information needed for disposition determination from the full packet data. Rather than analyzing all packet characteristics in real-time, the system identifies and extracts key contextual features (such as source/destination relationships, temporal patterns, and flow characteristics) that are most relevant to threat assessment, reducing computation time while maintaining accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If comprehensive threat context information is collected and analyzed, then disposition accuracy improves, but system complexity increases

Engineering Contradiction:
Improvethreat context assessment accuracyVSAvoidpacket filtering system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the threat context assessment into distinct modular components: packet flow observation, threat context information collection, evaluation logic, and disposition determination. Each component handles a specific aspect of the analysis independently, allowing the system to process comprehensive threat context information through specialized sub-systems rather than a monolithic complex structure, improving manageability and reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250358295A1Efficient Threat Context-Aware Packet Filtering for Network Protection
Publication Date: 2025.11.20 CENTRIPETAL NETWORKS INC
  • US20250358295A1 patent drawing
  • US20250358295A1 patent drawing
  • US20250358295A1 patent drawing

AI summary

A threat intelligence gateway (TIG) may protect TCP/IP networks from network (e.g., Internet) threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies may be composed of packet filtering rules with packet-matching criteria derived from cyber threat intelligence (CTI) associated with Internet threats. These CTI-derived packet-filtering rules may be created offline by policy creation and management servers, which may distribute the policies to subscribing TIGs that subsequently enforce the policies on in-transit packets. Each packet filtering rule may specify a disposition that may be applied to a matching in-transit packet, such as deny/block/drop the in-transit packet or pass/allow/forward the in-transit packet, and also may specify directives that may be applied to a matching in-transit packet, such as log, capture, spoof-tcp-rst, etc. Often, however, the selection of a rule's disposition and directives that best protect the associated network may not be optimally determined before a matching in-transit packet is observed by the associated TIG. In such cases, threat context information that may only be available (e.g., computable) at in-transit packet observation and/or filtering time, such as current time-of-day, current TIG/network location, current TIG/network administrator, the in-transit packet being determined to be part of an active attack on the network, etc., may be helpful to determine the disposition and directives that may best protect the network from the threat associated with the in-transit packet. The present disclosure describes examples of methods, systems, and apparatuses that may be used for efficiently determining (e.g., accessing and/or computing), in response to the in-transit packet, threat context information associated with an in-transit packet. The threat context information may be used to efficiently determine the disposition and/or one or more directives to apply to the in-transit packet. This may result in dispositions and/or directives being applied to in-transit packets that better protect the network as compared with solely using dispositions and directives that were predetermined prior to receiving the in-transit packet.