Cloud Malware Detection Subscription Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional malware detection appliances face performance degradation and scalability issues due to resource constraints as network traffic increases, requiring additional appliances and resulting in high capital costs and limited flexibility.
Innovation Solution
A subscription-based malware detection system with a scalable architecture that utilizes a cloud-based service connecting customers to an object evaluation service, allowing for flexible deployment and resource allocation through multi-tenancy, differentiated service levels, and dynamic cluster management to ensure performance and availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If additional malware detection appliances are installed to handle increased network traffic, then detection capacity is improved, but capital costs and deployment complexity increase
Solution Approach 1:
The patent combines multiple malware detection appliances into a single appliance that can handle multiple security policies and traffic streams simultaneously. The system allows one appliance to perform the work of multiple appliances by implementing a policy-based architecture where a single device can enforce different security policies on different network segments or traffic types, thereby reducing the number of physical devices needed while maintaining or improving detection capacity.
Solution Approach 2:
The malware detection appliance is designed with multi-functionality to perform various detection tasks across different network segments. A single appliance can simultaneously conduct deep packet inspection, flow analysis, and application-layer inspection for multiple different security policies, making it a universal device that replaces multiple specialized appliances and reduces overall system complexity.
2Reliability
If malware detection appliances are deployed to ensure security, then detection reliability is improved, but scalability is limited due to resource constraints
Solution Approach 1:
The system implements dynamic resource allocation and policy management that allows the malware detection appliance to adapt its behavior based on current network conditions and traffic patterns. The appliance can dynamically adjust inspection depth, allocate processing resources, and modify detection strategies in real-time, enabling it to maintain high detection reliability while scaling to handle varying network loads without requiring additional physical devices.
3Use of energy by moving object
If selective traffic inspection is implemented to conserve resources, then resource utilization is improved, but detection thoroughness deteriorates
Solution Approach 1:
The system applies different inspection levels to different portions of traffic based on local characteristics. Rather than uniformly inspecting all traffic or selectively inspecting only certain flows, the appliance performs deep, thorough inspection on suspicious or high-risk traffic while using lighter inspection methods on benign traffic. This local quality approach ensures detection thoroughness is maintained where needed while conserving resources on low-risk traffic.
Solution Approach 2:
The malware detection appliance performs partial inspection on most traffic and excessive (deep) inspection on suspicious traffic. Rather than applying the same level of inspection to all packets, the system uses initial screening to identify suspicious traffic and then applies comprehensive inspection only where necessary, achieving both resource efficiency and detection thoroughness through differentiated inspection intensity.
Data Source
AI summary
A system featuring a cloud-based malware detection system for analyzing an object to determine whether the object is associated with a cyber-attack. Herein, subscription review service comprises a data store storing subscription information. The subscription information includes identifier for the customer and one or more identifiers each associated with a corresponding customer submitter operable to submit an object to the cloud-based malware detection system for analysis. The first customer submitter receives credentials provided by the subscription review service to establish communications with the cloud-based malware detection system. The first customer submitter includes a first submitter identifier that comprises (i) enforcement logic that enforces compliance with a plurality of requirements of the subscription to the cloud-based malware detection system and (ii) reporting logic that transmits a result of the analysis of the object by the cloud-based malware detection system in determining whether the object is associated with a cyber-attack.


