Cross-Product Security Controller for Advanced Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional anti-virus and anti-malware solutions are reactive and unable to cope with the exponential growth in sophisticated malware attacks, which are often silent and target fewer machines, making them ineffective in detecting and addressing advanced threat vectors.

Innovation Solution

An advanced threat protection cross-product security controller that integrates multiple security applications to aggregate, summarize, and present contexts related to suspicious activities, enabling remediation workflows and automatic actions by monitoring networks and clients, using techniques like sandboxing, threat intelligence, and behavior analysis to identify and respond to malware threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus and anti-malware solutions are used, then the system structure remains simple, but the ability to detect and respond to sophisticated malware attacks deteriorates

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsecurity system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is divided into multiple independent security applications (antivirus, anti-malware, host intrusion prevention, email security, web security) that can be selectively deployed. Each application focuses on specific threat vectors, allowing the system to achieve comprehensive protection while maintaining modular simplicity where only needed components are activated.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security controller provides universal protection across multiple platforms and threat types through a single integrated system. It can manage diverse security applications (antivirus, anti-malware, HIPS, email security, web security) and coordinate them to address various attack vectors including file-based malware, email-borne threats, and web-based attacks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of time

If traditional reactive anti-virus solutions are used, then the system resource consumption remains low, but the response time to sophisticated malware attacks deteriorates

Engineering Contradiction:
Improveresponse time to malware attacksVSAvoidsystem resource consumption
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by proactively monitoring and analyzing files, emails, and web traffic before threats can execute or spread. Security applications continuously scan and validate content in advance, enabling the system to detect and block sophisticated malware attacks before they compromise systems, rather than reacting after infection occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security controller implements feedback mechanisms where security applications continuously report threat detections and system states back to the controller. This enables real-time coordination and response, allowing the system to dynamically adjust security measures based on current threat levels and successfully detect and respond to malware attacks as they emerge.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If traditional single-vector anti-malware solutions are used, then the system complexity remains low, but the coverage of threat detection deteriorates

Engineering Contradiction:
Improvethreat detection coverageVSAvoidsecurity application integration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security system is divided into multiple independent security applications (antivirus, anti-malware, host intrusion prevention, email security, web security) that can be selectively deployed. Each application focuses on specific threat vectors, allowing the system to achieve comprehensive protection while maintaining modular simplicity where only needed components are activated.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security controller provides universal protection across multiple platforms and threat types through a single integrated system. It can manage diverse security applications (antivirus, anti-malware, HIPS, email security, web security) and coordinate them to address various attack vectors including file-based malware, email-borne threats, and web-based attacks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12079336B2Advanced threat protection cross-product security controller
Publication Date: 2024.09.03 MAGENTA SECURITY HOLDINGS LLC
  • US12079336B2 patent drawing
  • US12079336B2 patent drawing
  • US12079336B2 patent drawing

AI summary

A system for securing electronic devices includes a processor, non-transitory machine readable storage medium communicatively coupled to the processor, security applications, and a security controller. The security controller includes computer-executable instructions on the medium that are readable by the processor. The security application is configured to determine a suspicious file from a client using the security applications, identify whether the suspicious file has been encountered by other clients using the security applications, calculate a time range for which the suspicious file has been present on the clients, determine resources accessed by the suspicious file during the time range, and create a visualization of the suspicious file, a relationship between the suspicious file and the clients, the time range, and the resources accessed by the suspicious file during the time range.