Distributed Sensor Network for Real-Time Malware Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for remediating security threats from compromised computers infected with bots and malware are ineffective, slow, or incomplete, particularly in identifying and mitigating attacks originating from attacker computers located behind firewalls or operated by malicious state actors.
Innovation Solution
A distributed network of sensor computers is deployed near compromised computers to detect and analyze network messages, identify security threats, and implement remediation measures such as dropping packets or disrupting connections, while a security control computer processes detection data to determine and execute remediation strategies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If distributed sensor computers are deployed to detect and analyze network messages in real-time, then security threat detection capability is improved, but device complexity increases
Solution Approach 1:
The system divides the security monitoring function into distributed sensor computers, each independently monitoring network messages from compromised computers. Each sensor computer is a simple device that collects data and forwards it to a central security control computer for analysis, segmenting the complex monitoring task into manageable units.
Solution Approach 2:
The sensor computers act as intermediaries between compromised computers and the security control computer. They collect network message data without directly interfering with the compromised computers' operations, and forward processed detection data to the central system for threat analysis and remediation decision-making.
2Reliability
If real-time detection and remediation of security threats is implemented, then security effectiveness is improved, but loss of time in processing is reduced (faster processing needed)
Solution Approach 1:
The sensor computers continuously monitor and collect network message data from compromised computers in advance, maintaining a ready supply of detection data. When a security threat is suspected, the data is already collected and can be immediately analyzed by the security control computer, eliminating data collection delays during incident response.
Solution Approach 2:
The system maintains continuous monitoring of network messages from compromised computers through distributed sensor computers. This uninterrupted data collection ensures that security threats are detected immediately upon occurrence, enabling real-time response without gaps in surveillance.
3Measurement precision
If comprehensive detection data is collected from distributed sensor computers, then measurement precision of threats is improved, but quantity of data to process increases
Solution Approach 1:
The sensor computers extract only the essential features and metadata from network messages, such as source IP addresses, destination addresses, message types, and timing information. This extraction approach captures the critical elements needed for threat detection while excluding unnecessary data, reducing the overall data volume requiring central processing.
Solution Approach 2:
The system collects slightly more data than the absolute minimum required, including comprehensive metadata from all network messages. This partial excess ensures that sufficient information is available for accurate threat analysis while the distributed architecture manages the data load efficiently across multiple sensor computers.
Data Source
AI summary
A computer-implemented method, comprising: detecting network messages that are emitted by a compromised computer, wherein the compromised computer comprises at least one malware item that is configured to direct unauthorized network activity toward one or more enterprise networks or enterprise computers; queuing copies of the network messages in a queue; forwarding the network messages to original destinations; determining whether the number of network messages exceeds a specified threshold associated with an attack vector; filtering by the processor, the copies that do not include one of a set of port values associated with known computer attacks; analyzing, by the processor, timing of the copies with respect to a predetermined schedule including active hours and inactive hours, detecting one or more security threats caused by the comprised computer based on the determining, filtering, and the analyzing, sending a result of the detecting to a security control computer over a communication network.


