Varifocal Threat Analysis Across Local, Regional, and Global Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat intelligence systems in communications networks are limited by their single-perspective view, failing to recognize localized attacks like DDoS as they do not trigger mitigation actions unless overall network traffic thresholds are exceeded, and local systems lack information from other local computing systems.
Innovation Solution
Implementing a varifocal threat analysis system that monitors network traffic at local, regional, and global levels, using collectors to gather data, identify threats, and apply mitigation actions based on local, regional, and global thresholds, with amplification factors to accelerate response to spreading threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a single global threshold is used for threat detection across the entire network, then the system can maintain simple operation and unified control, but it fails to detect localized attacks (like DDoS) that do not exceed the overall network traffic threshold
Solution Approach 1:
The patent divides the network monitoring system into multiple hierarchical levels: local computing systems (individual nodes), regional aggregation points (groups of nodes), and global network level. Each level has its own threat detection thresholds and analysis capabilities. This segmentation enables localized attack detection at the node level while maintaining overall network context at higher levels, resolving the contradiction between detection precision and system simplicity.
2Speed
If local computing systems operate independently with their own threat detection, then each system can respond quickly to local threats, but local systems lack information from other systems and cannot recognize coordinated attacks
Solution Approach 1:
The patent implements feedback loops where threat intelligence and traffic information flow upward from local computing systems to regional and global levels, and mitigation decisions flow downward. Local systems receive feedback about regional and global threat patterns, enabling them to recognize coordinated attacks while maintaining fast local response capabilities. This hierarchical feedback mechanism resolves the contradiction between rapid local response and comprehensive threat intelligence.
3Reliability
If mitigation actions are applied globally across the entire network, then the system can provide unified security coverage, but it creates unnecessary burden on components not under attack and cannot dynamically scope responses
Solution Approach 1:
The patent enables different mitigation actions and threshold levels at different hierarchical levels and geographic regions. When a threat is detected at the local level, mitigation is applied only to affected local computing systems. When threats escalate to regional or global levels, broader mitigation is applied proportionally. This local quality approach ensures comprehensive security coverage while minimizing unnecessary resource consumption on unaffected network components.
4Measurement precision
If local threshold values are set low for sensitive detection, then localized attacks can be detected early, but false positives increase and normal traffic variations are misidentified as threats
Solution Approach 1:
The patent adds hierarchical dimensions to threat detection by implementing local, regional, and global analysis layers. Local systems use sensitive thresholds for early detection, while regional and global levels provide contextual validation by analyzing aggregated traffic patterns across multiple nodes. A local detection must be consistent with regional and global patterns to be confirmed as a true threat, reducing false positives while maintaining high detection sensitivity at the local level.
Data Source
AI summary
Example systems and methods permit threat intelligence to be determined and used at a local, regional, and/or global level in a communications network. A threat intelligence system may collect traffic information from local computing systems and analyze it for malicious traffic. If a measure of malicious traffic in a local computing system is reached, mitigation actions may be taken in that local computing system. In addition, threat measures may be amplified in other local computing systems, other regions, or globally in the network, in order to more quickly react to a known threat as it may spread in a network.


