Threat Index-Based Packet Storage Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional packet storage solutions, configured on a first-in, first-out (FIFO) basis, fail to prioritize stored network traffic data effectively for incident response testing, leading to cost inefficiencies due to the delayed detection of network breaches and the inability to retain valuable data associated with malicious events.

Innovation Solution

A security architecture that assigns retention priorities to stored content based on threat index values, which are computed from flow attributes such as node, group affiliation, destination, and object types, allowing for the prioritization and efficient eviction of storage blocks to maintain valuable data for incident response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If conventional FIFO packet storage solutions are used to reclaim physical storage, then storage space is recovered, but valuable data associated with malicious events is lost

Engineering Contradiction:
Improvestorage spaceVSAvoidvaluable data associated with malicious events
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The patent changes the storage management parameter from time-based FIFO eviction to threat-based priority eviction. Each packet is assigned a threat index value, and eviction decisions are made based on these values rather than storage time. This allows the system to retain high-value malicious packets while evicting low-value benign packets, resolving the contradiction between reclaiming storage space and preserving valuable information.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies different retention policies to different packets based on their individual threat index values. Instead of a uniform FIFO policy, each packet receives localized quality assessment through threat indexing, allowing high-threat packets to be retained while low-threat packets are evicted. This local differentiation resolves the contradiction by preserving valuable malicious data while still reclaiming storage space from less valuable packets.

Inventive Principle:
Principle #3Local quality

2Reliability

If vast amounts of network traffic data are persistently stored for incident response testing, then security analysis capability is improved, but storage costs become prohibitive

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoidstorage cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces threat index values as a new parameter to differentiate packet importance. By storing only high-threat-index packets rather than all packets, the system maintains security analysis capability while dramatically reducing storage requirements. This parameter-based filtering resolves the contradiction between maintaining reliable security analysis and controlling storage costs.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts and retains only the valuable subset of packets (those with high threat index values) while discarding the majority of benign traffic. This extraction approach allows the system to maintain effective security analysis capability by focusing on malicious packets only, thereby reducing storage costs while preserving reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of information

If all network packets are retained indefinitely for incident response, then complete forensic data is available, but storage resources are exhausted

Engineering Contradiction:
Improveforensic data completenessVSAvoidstorage resources
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent changes the retention criterion from indefinite time-based retention to threat-value-based retention. Packets are retained based on their threat index values rather than how long they have been stored. This ensures that forensic data completeness is maintained for high-value packets while storage resources are preserved by evicting low-value packets, resolving the contradiction between information retention and resource consumption.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10521358B2System, apparatus and method for prioritizing the storage of content based on a threat index
Publication Date: 2019.12.31 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10521358B2 patent drawing
  • US10521358B2 patent drawing
  • US10521358B2 patent drawing

AI summary

A network sensor that features a data store and a packet processing engine. Communicatively coupled to the data store, the packet processing engine is configured to (i) generate a retention priority for at least a first flow within a first storage region of a plurality of storage regions and (ii) identify, in response to an eviction request, the priority of each of the plurality of storage regions. The priority of the first storage region is partially based on the retention priority associated with the first flow while the priority of a second storage region is based on retention priorities associated with flows stored within the second storage region. The packet processing engine also is configured to identify, through use of the retention priorities of the stored flows within the first storage region, which flows are to be retained and which flows are to be evicted.