Automated Binary Signature Identification for Security Policy Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data loss prevention systems face challenges in timely and effective generation of security policies for file format types, as they often require manual intervention and lack automated methods for identifying common binary signatures, which hampers prompt response to potential security threats.

Innovation Solution

A system and method that automatically identifies common binary signatures in a set of files with the same file format type, allowing for the generation and deployment of an electronic security policy using a user-friendly interface, thereby enabling efficient and timely security policy generation and enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual intervention is used for generating security policies, then policy generation can be performed with existing systems, but the response time to security threats is delayed and productivity is reduced

Engineering Contradiction:
Improvepolicy generation speedVSAvoidmanual intervention requirement
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system automatically performs binary signature identification and security policy generation without requiring manual analyst intervention. The automated binary signature identifier scans files, extracts signatures, and the policy generator creates security policies based on these signatures, enabling the system to serve itself and eliminate human bottlenecks in the security policy creation process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by automatically identifying binary signatures and generating security policies in advance before security threats materialize. This proactive approach allows security policies to be ready and deployed immediately when threats are detected, eliminating the delay associated with manual policy creation after incidents occur.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If automated binary signature identification is implemented, then response time to security threats is reduced, but system complexity increases

Engineering Contradiction:
Improveresponse time to threatsVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system divides the security policy generation process into distinct modular components: a binary signature identifier module that extracts signatures from files, a policy generator module that creates security policies, and a deployment module that distributes policies. This segmentation allows each component to be independently optimized and managed, reducing overall system complexity while enabling rapid automated response to threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary automated binary signature identification system that acts as a bridge between raw file data and security policy requirements. This intermediary automatically extracts and analyzes binary signatures, transforming unstructured file data into structured security policy inputs, thereby reducing the complexity burden on the overall system while maintaining fast response times.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated policy generation is deployed, then processor efficiency is improved, but the initial implementation complexity increases

Engineering Contradiction:
Improveprocessor efficiencyVSAvoidimplementation ease
Core Design Contradiction:
ProductivityVSEase of manufacture

Solution Approach 1:

The system replaces manual mechanical processes of security policy creation with automated computational processes. The automated binary signature identifier and policy generator use algorithmic methods to scan files, extract signatures, and generate policies, substituting human analysts and manual procedures with efficient computer-based automation that improves processor efficiency while managing implementation complexity through standardized software workflows.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11562093B2System for generating an electronic security policy for a file format type
Publication Date: 2023.01.24 FORCEPOINT LLC
  • US11562093B2 patent drawing
  • US11562093B2 patent drawing
  • US11562093B2 patent drawing

AI summary

A method, system, and computer-readable storage medium are disclosed for identifying binary signatures in a selected set of files and assigning at least one of the binary signatures to a file format name or file format type for use in a security policy generator. In certain embodiments, the method for generating an electronic security policy for a file format type, includes: identification of a plurality of files stored in electronic memory, where the plurality of files include files having the same file format type; providing a file format name that is to be associated with the file format type; accessing the plurality of files from the electronic memory; identifying a common binary signature for the file format type included in the plurality of files; correlating the file format type with the common binary signature; and generating the security policy for the file format type using the file format name.