Integrated Behavioral and Signature Security System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Anti-Virus (AV) applications face a 'day zero' problem where they are blind to new viruses until a signature is developed and deployed, leading to a window of vulnerability as they rely solely on signature matching, which is ineffective during the lag time before detection and analysis by vendors.

Innovation Solution

An integrated approach combining behavioral and signature-based methods, where behavioral heuristics analyze actions indicative of malicious activity and generate real-time signatures to identify and quarantine malware, thereby mitigating the day zero problem by providing immediate protection against unknown viruses and known threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional signature-based AV applications are used, then high accuracy in matching known undesirable transmissions is achieved, but a window of vulnerability exists during the lag time before new virus signatures are deployed

Engineering Contradiction:
Improveaccuracy in matching known undesirable transmissionsVSAvoidprotection against new viruses during lag time
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary behavioral analysis on incoming transmissions before signature matching is available. By monitoring actions, operations, and behavior patterns of the transmitting entity in advance, the system can identify potentially malicious transmissions during the lag time before new signatures are deployed, thus protecting against new viruses while maintaining high accuracy for known threats

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces behavioral analysis as an intermediary mechanism between the incoming transmission and the signature matching process. This intermediary layer analyzes behavior patterns, actions, and operations to provide preliminary identification of malicious transmissions, bridging the gap during the signature deployment lag time and enabling both high accuracy matching and continuous protection against new threats

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If behavioral heuristics are used to analyze actions indicative of malicious activity, then protection against unknown viruses is provided in real-time, but system complexity increases

Engineering Contradiction:
Improveprotection against unknown virusesVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges behavioral analysis and signature-based detection into a single integrated security system. By combining these two approaches, the system achieves both real-time protection against unknown viruses through behavioral heuristics and high accuracy matching of known threats through signatures, while sharing common infrastructure such as the transmission monitoring module and entity identification mechanisms, thus managing complexity through integration rather than separate systems

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7694150B1System and methods for integration of behavioral and signature based security
Publication Date: 2010.04.06 CISCO TECHNOLOGY INC
  • US7694150B1 patent drawing
  • US7694150B1 patent drawing
  • US7694150B1 patent drawing

AI summary

Conventional matching approaches to virus detection are ineffective pending deployment of a signature to match a newly discovered virus. In contrast, a behavioral based (subject) approach addresses the so-called “day zero” problem of object matching approaches. An integrated approach combines the behavioral remedy against unknown transmissions with the signature matching of known harmful transmission to provide the reliability and stability of signature based approaches with the real time responsiveness of the behavioral approach. A behavior monitoring module analyzes actions via behavioral heuristics indicative of actions performed by known harmful transmissions. The behavioral monitoring correlates the actions performed to determine an undesirable object. A signature generator computes a realtime signature on the suspect object. The signature generator accumulates successive realtime signatures in this manner for comparison with subsequent incoming transmissions, thus combining the subject based behavioral aspects of virus detection with the deterministic aspects of the object approach.