Cybersecurity Intelligence Hub for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection systems face performance degradation with increasing network traffic, particularly in detecting advanced or unknown malware due to limited accessibility to cybersecurity intelligence, and lack effective methods for rapid malicious object detection, increased accuracy, and enhanced visibility of cyber-attacks.

Innovation Solution

A comprehensive cybersecurity platform featuring a cybersecurity intelligence hub that parses, formats, stores, manages, updates, analyzes, and distributes cybersecurity intelligence across a global data store, providing meta-information for artifact classification and generating additional intelligence to enhance cyber-attack detection and response, while reducing network throughput and mitigating repetitive analytics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malware detection devices are placed at the periphery of the enterprise network to analyze network traffic, then known malware can be detected successfully, but performance decreases and detection accuracy for advanced malware deteriorates as network traffic increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddetection performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a centralized malware detection system as an intermediary between network traffic and analysis resources. This central system receives traffic from multiple periphery devices, consolidates analysis requests, and distributes workloads efficiently, preventing performance degradation while maintaining detection accuracy for both known and advanced malware

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges multiple periphery malware detection devices into a single centralized system that consolidates network traffic analysis. This combination allows shared access to cybersecurity intelligence resources and coordinated analysis capabilities, improving overall detection performance without sacrificing reliability

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If periphery malware detection devices conduct independent analysis of suspicious information, then detection can proceed without centralized coordination, but accessibility to cybersecurity intelligence is limited

Engineering Contradiction:
Improveindependent detection capabilityVSAvoidaccessibility to cybersecurity intelligence
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The centralized malware detection system acts as an intermediary that maintains independent detection capabilities at periphery devices while providing enhanced access to cybersecurity intelligence. The central system aggregates intelligence from multiple sources and distributes it to periphery devices, eliminating information loss without reducing operational independence

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the malware detection function into periphery components that maintain independent operational capability and a central component that provides enhanced intelligence access. This segmentation allows local devices to continue independent analysis while the central system supplements them with broader cybersecurity intelligence

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11240275B1Platform and method for performing cybersecurity analyses employing an intelligence hub with a modular architecture
Publication Date: 2022.02.01 MAGENTA SECURITY HOLDINGS LLC
  • US11240275B1 patent drawing
  • US11240275B1 patent drawing
  • US11240275B1 patent drawing

AI summary

A network device for collecting and distributing cybersecurity intelligence, which features analytics logic and a plurality of plug-ins. The analytics logic is configured to (i) receive a request message to conduct a cybersecurity analysis and (ii) select one of a first set or second set of plug-ins to conduct the cybersecurity analysis. Responsive to selecting a first plug-in of the first set of plug-ins by the analytics logic, the system conducts and completes the cybersecurity analysis while a communication session between the first plug-in and a network device initiating the request message remains open. Responsive to selecting a second plug-in by the analytics logic, the system conducts and completes the cybersecurity analysis while allowing the cybersecurity intelligence to be provided in response to the request message during a different and subsequent communication session than the communication session during which the request message is received.