Distributed Sensor Network for Real-Time Malware Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for remediating security threats from compromised computers infected with bots and malware are ineffective, slow, or incomplete, particularly in identifying and mitigating attacks originating from attacker computers located behind firewalls or operated by malicious state actors.

Innovation Solution

A distributed network of sensor computers is deployed near compromised computers to detect and analyze network messages, identify security threats, and implement remediation measures such as dropping packets or disrupting connections, while a security control computer processes detection data to determine and execute remediation strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If distributed sensor computers are deployed to detect and analyze network messages in real-time, then security threat detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system divides the security monitoring function into distributed sensor computers, each independently monitoring network messages from compromised computers. Each sensor computer is a simple device that collects data and forwards it to a central security control computer for analysis, segmenting the complex monitoring task into manageable units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The sensor computers act as intermediaries between compromised computers and the security control computer. They collect network message data without directly interfering with the compromised computers' operations, and forward processed detection data to the central system for threat analysis and remediation decision-making.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time detection and remediation of security threats is implemented, then security effectiveness is improved, but loss of time in processing is reduced (faster processing needed)

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The sensor computers continuously monitor and collect network message data from compromised computers in advance, maintaining a ready supply of detection data. When a security threat is suspected, the data is already collected and can be immediately analyzed by the security control computer, eliminating data collection delays during incident response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous monitoring of network messages from compromised computers through distributed sensor computers. This uninterrupted data collection ensures that security threats are detected immediately upon occurrence, enabling real-time response without gaps in surveillance.

Inventive Principle:
Principle #20Continuity of useful action

3Measurement precision

If comprehensive detection data is collected from distributed sensor computers, then measurement precision of threats is improved, but quantity of data to process increases

Engineering Contradiction:
Improvethreat identification accuracyVSAvoiddetection data volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The sensor computers extract only the essential features and metadata from network messages, such as source IP addresses, destination addresses, message types, and timing information. This extraction approach captures the critical elements needed for threat detection while excluding unnecessary data, reducing the overall data volume requiring central processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system collects slightly more data than the absolute minimum required, including comprehensive metadata from all network messages. This partial excess ensures that sufficient information is available for accurate threat analysis while the distributed architecture manages the data load efficiently across multiple sensor computers.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10084815B2Remediating computer security threats using distributed sensor computers
Publication Date: 2018.09.25 CLOUDFLARE INC
  • US10084815B2 patent drawing
  • US10084815B2 patent drawing
  • US10084815B2 patent drawing

AI summary

A computer-implemented method, comprising: detecting network messages that are emitted by a compromised computer, wherein the compromised computer comprises at least one malware item that is configured to direct unauthorized network activity toward one or more enterprise networks or enterprise computers; queuing copies of the network messages in a queue; forwarding the network messages to original destinations; determining whether the number of network messages exceeds a specified threshold associated with an attack vector; filtering by the processor, the copies that do not include one of a set of port values associated with known computer attacks; analyzing, by the processor, timing of the copies with respect to a predetermined schedule including active hours and inactive hours, detecting one or more security threats caused by the comprised computer based on the determining, filtering, and the analyzing, sending a result of the detecting to a security control computer over a communication network.