Cloud API Malicious Behavior Mitigation for Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security approaches rely heavily on hardware-specific solutions, such as firewalls, which are limited in their ability to provide comprehensive security for applications operating outside of a protected network environment.

Innovation Solution

A cloud-based malicious behavior mitigation system that provides abstracted network and data security services through a published API, allowing applications to integrate security functions like antivirus, sandbox, and IP reputation checks, enabling hardware-agnostic security without the need for specific hardware configurations or administration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If applications rely on network security devices like firewalls for protection, then network-level security is improved, but applications operating outside protected networks cannot receive security protection

Engineering Contradiction:
Improvenetwork securityVSAvoidapplication deployment flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a cloud-based malicious behavior mitigation system as an intermediary between applications and security protection. The application calls security functions directly through API interfaces, and the cloud system provides the actual security services, mediating the protection delivery regardless of network environment

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The application integrates security function calls directly into its code, enabling it to autonomously request security services from the cloud-based mitigation system without requiring external network security devices. This self-service capability allows the application to maintain security protection across different deployment environments

Inventive Principle:
Principle #25Self-service

2Reliability

If hardware-specific security devices are used, then security enforcement capability is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvesecurity enforcementVSAvoidhardware configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces hardware-based security enforcement mechanisms with software-based API calls to cloud services. Instead of relying on physical security devices and their configurations, the system uses standardized software interfaces that can be integrated into applications without hardware dependencies

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The cloud-based malicious behavior mitigation system provides universal security services that can be accessed by applications across different hardware platforms and network environments. The single cloud system replaces multiple hardware-specific security devices, providing multi-functional security protection

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If applications integrate direct security function calls to cloud services, then security adaptability across environments is improved, but network dependency increases

Engineering Contradiction:
Improveenvironmental adaptabilityVSAvoidnetwork dependency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary security checks by calling cloud-based mitigation functions before applications process or execute potentially malicious content. This advance security validation ensures that security protection is in place before potential threats materialize, reducing the impact of network dependency during critical operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11816207B2Systems and methods for application integrated malicious behavior mitigation
Publication Date: 2023.11.14 FORTINET INC
  • US11816207B2 patent drawing
  • US11816207B2 patent drawing
  • US11816207B2 patent drawing

AI summary

Various embodiments discussed generally relate to securing applications that work across networks, and more particularly to systems and methods for mitigating malicious behavior integrated within an application that directly calls a separate cloud based malicious behavior mitigation system.