Cloud Malware Detection Subscription Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional malware detection appliances face performance degradation and scalability issues due to resource constraints as network traffic increases, requiring additional appliances and resulting in high capital costs and limited flexibility.

Innovation Solution

A subscription-based malware detection system with a scalable architecture that utilizes a cloud-based service connecting customers to an object evaluation service, allowing for flexible deployment and resource allocation through multi-tenancy, differentiated service levels, and dynamic cluster management to ensure performance and availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If additional malware detection appliances are installed to handle increased network traffic, then detection capacity is improved, but capital costs and deployment complexity increase

Engineering Contradiction:
Improvedetection capacityVSAvoiddeployment complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent combines multiple malware detection appliances into a single appliance that can handle multiple security policies and traffic streams simultaneously. The system allows one appliance to perform the work of multiple appliances by implementing a policy-based architecture where a single device can enforce different security policies on different network segments or traffic types, thereby reducing the number of physical devices needed while maintaining or improving detection capacity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The malware detection appliance is designed with multi-functionality to perform various detection tasks across different network segments. A single appliance can simultaneously conduct deep packet inspection, flow analysis, and application-layer inspection for multiple different security policies, making it a universal device that replaces multiple specialized appliances and reduces overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If malware detection appliances are deployed to ensure security, then detection reliability is improved, but scalability is limited due to resource constraints

Engineering Contradiction:
Improvedetection reliabilityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic resource allocation and policy management that allows the malware detection appliance to adapt its behavior based on current network conditions and traffic patterns. The appliance can dynamically adjust inspection depth, allocate processing resources, and modify detection strategies in real-time, enabling it to maintain high detection reliability while scaling to handle varying network loads without requiring additional physical devices.

Inventive Principle:
Principle #15Dynamics

3Use of energy by moving object

If selective traffic inspection is implemented to conserve resources, then resource utilization is improved, but detection thoroughness deteriorates

Engineering Contradiction:
Improveresource utilizationVSAvoiddetection thoroughness
Core Design Contradiction:
Use of energy by moving objectVSManufacturing precision

Solution Approach 1:

The system applies different inspection levels to different portions of traffic based on local characteristics. Rather than uniformly inspecting all traffic or selectively inspecting only certain flows, the appliance performs deep, thorough inspection on suspicious or high-risk traffic while using lighter inspection methods on benign traffic. This local quality approach ensures detection thoroughness is maintained where needed while conserving resources on low-risk traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The malware detection appliance performs partial inspection on most traffic and excessive (deep) inspection on suspicious traffic. Rather than applying the same level of inspection to all packets, the system uses initial screening to identify suspicious traffic and then applies comprehensive inspection only where necessary, achieving both resource efficiency and detection thoroughness through differentiated inspection intensity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10848397B1System and method for enforcing compliance with subscription requirements for cyber-attack detection service
Publication Date: 2020.11.24 MAGENTA SECURITY HOLDINGS LLC
  • US10848397B1 patent drawing
  • US10848397B1 patent drawing
  • US10848397B1 patent drawing

AI summary

A system featuring a cloud-based malware detection system for analyzing an object to determine whether the object is associated with a cyber-attack. Herein, subscription review service comprises a data store storing subscription information. The subscription information includes identifier for the customer and one or more identifiers each associated with a corresponding customer submitter operable to submit an object to the cloud-based malware detection system for analysis. The first customer submitter receives credentials provided by the subscription review service to establish communications with the cloud-based malware detection system. The first customer submitter includes a first submitter identifier that comprises (i) enforcement logic that enforces compliance with a plurality of requirements of the subscription to the cloud-based malware detection system and (ii) reporting logic that transmits a result of the analysis of the object by the cloud-based malware detection system in determining whether the object is associated with a cyber-attack.