Cybersecurity Intelligence Hub for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection systems face performance degradation with increasing network traffic, particularly in detecting advanced or unknown malware due to limited accessibility to cybersecurity intelligence, and lack effective methods for rapid malicious object detection, increased accuracy, and enhanced visibility of cyber-attacks.
Innovation Solution
A comprehensive cybersecurity platform featuring a cybersecurity intelligence hub that parses, formats, stores, manages, updates, analyzes, and distributes cybersecurity intelligence across a global data store, providing meta-information for artifact classification and generating additional intelligence to enhance cyber-attack detection and response, while reducing network throughput and mitigating repetitive analytics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If malware detection devices are placed at the periphery of the enterprise network to analyze network traffic, then known malware can be detected successfully, but performance decreases and detection accuracy for advanced malware deteriorates as network traffic increases
Solution Approach 1:
The patent introduces a centralized malware detection system as an intermediary between network traffic and analysis resources. This central system receives traffic from multiple periphery devices, consolidates analysis requests, and distributes workloads efficiently, preventing performance degradation while maintaining detection accuracy for both known and advanced malware
Solution Approach 2:
The patent merges multiple periphery malware detection devices into a single centralized system that consolidates network traffic analysis. This combination allows shared access to cybersecurity intelligence resources and coordinated analysis capabilities, improving overall detection performance without sacrificing reliability
2Ease of operation
If periphery malware detection devices conduct independent analysis of suspicious information, then detection can proceed without centralized coordination, but accessibility to cybersecurity intelligence is limited
Solution Approach 1:
The centralized malware detection system acts as an intermediary that maintains independent detection capabilities at periphery devices while providing enhanced access to cybersecurity intelligence. The central system aggregates intelligence from multiple sources and distributes it to periphery devices, eliminating information loss without reducing operational independence
Solution Approach 2:
The patent segments the malware detection function into periphery components that maintain independent operational capability and a central component that provides enhanced intelligence access. This segmentation allows local devices to continue independent analysis while the central system supplements them with broader cybersecurity intelligence
Data Source
AI summary
A network device for collecting and distributing cybersecurity intelligence, which features analytics logic and a plurality of plug-ins. The analytics logic is configured to (i) receive a request message to conduct a cybersecurity analysis and (ii) select one of a first set or second set of plug-ins to conduct the cybersecurity analysis. Responsive to selecting a first plug-in of the first set of plug-ins by the analytics logic, the system conducts and completes the cybersecurity analysis while a communication session between the first plug-in and a network device initiating the request message remains open. Responsive to selecting a second plug-in by the analytics logic, the system conducts and completes the cybersecurity analysis while allowing the cybersecurity intelligence to be provided in response to the request message during a different and subsequent communication session than the communication session during which the request message is received.


