Varifocal Threat Analysis Across Local, Regional, and Global Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat intelligence systems in communications networks are limited by their single-perspective view, failing to recognize localized attacks like DDoS as they do not trigger mitigation actions unless overall network traffic thresholds are exceeded, and local systems lack information from other local computing systems.

Innovation Solution

Implementing a varifocal threat analysis system that monitors network traffic at local, regional, and global levels, using collectors to gather data, identify threats, and apply mitigation actions based on local, regional, and global thresholds, with amplification factors to accelerate response to spreading threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a single global threshold is used for threat detection across the entire network, then the system can maintain simple operation and unified control, but it fails to detect localized attacks (like DDoS) that do not exceed the overall network traffic threshold

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the network monitoring system into multiple hierarchical levels: local computing systems (individual nodes), regional aggregation points (groups of nodes), and global network level. Each level has its own threat detection thresholds and analysis capabilities. This segmentation enables localized attack detection at the node level while maintaining overall network context at higher levels, resolving the contradiction between detection precision and system simplicity.

Inventive Principle:
Principle #1Segmentation

2Speed

If local computing systems operate independently with their own threat detection, then each system can respond quickly to local threats, but local systems lack information from other systems and cannot recognize coordinated attacks

Engineering Contradiction:
Improveresponse speedVSAvoidthreat intelligence
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent implements feedback loops where threat intelligence and traffic information flow upward from local computing systems to regional and global levels, and mitigation decisions flow downward. Local systems receive feedback about regional and global threat patterns, enabling them to recognize coordinated attacks while maintaining fast local response capabilities. This hierarchical feedback mechanism resolves the contradiction between rapid local response and comprehensive threat intelligence.

Inventive Principle:
Principle #23Feedback

3Reliability

If mitigation actions are applied globally across the entire network, then the system can provide unified security coverage, but it creates unnecessary burden on components not under attack and cannot dynamically scope responses

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent enables different mitigation actions and threshold levels at different hierarchical levels and geographic regions. When a threat is detected at the local level, mitigation is applied only to affected local computing systems. When threats escalate to regional or global levels, broader mitigation is applied proportionally. This local quality approach ensures comprehensive security coverage while minimizing unnecessary resource consumption on unaffected network components.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If local threshold values are set low for sensitive detection, then localized attacks can be detected early, but false positives increase and normal traffic variations are misidentified as threats

Engineering Contradiction:
Improveattack detection sensitivityVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent adds hierarchical dimensions to threat detection by implementing local, regional, and global analysis layers. Local systems use sensitive thresholds for early detection, while regional and global levels provide contextual validation by analyzing aggregated traffic patterns across multiple nodes. A local detection must be consistent with regional and global patterns to be confirmed as a true threat, reducing false positives while maintaining high detection sensitivity at the local level.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12563074B2Varifocal threat analysis system and method
Publication Date: 2026.02.24 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US12563074B2 patent drawing
  • US12563074B2 patent drawing
  • US12563074B2 patent drawing

AI summary

Example systems and methods permit threat intelligence to be determined and used at a local, regional, and/or global level in a communications network. A threat intelligence system may collect traffic information from local computing systems and analyze it for malicious traffic. If a measure of malicious traffic in a local computing system is reached, mitigation actions may be taken in that local computing system. In addition, threat measures may be amplified in other local computing systems, other regions, or globally in the network, in order to more quickly react to a known threat as it may spread in a network.