Dynamic File Routing Between Cloud and On-Premise Malware Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in selecting an appropriate malware analysis system between cloud-based and on-premise options, balancing security, privacy, and cost, while existing solutions either compromise on security or incur high computational expenses for on-premise systems or sacrifice privacy for cost-effective cloud solutions.

Innovation Solution

A network security element that dynamically selects between off-premise and on-premise malware analysis systems based on session, file, and system attributes, such as confidentiality level, geolocation, and processing capacity, to ensure secure, private, and cost-effective file analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Power

If cloud-based malware analysis service is used, then computational power and cost-effectiveness are improved, but privacy and data confidentiality are compromised

Engineering Contradiction:
Improvecomputational powerVSAvoiddata confidentiality
Core Design Contradiction:
PowerVSLoss of information

Solution Approach 1:

The system segments the malware analysis functionality into two distinct deployment options: cloud-based analysis systems and on-premise analysis systems. This segmentation allows organizations to divide their analysis workload between public and private infrastructure, enabling them to send non-sensitive files to cloud systems for cost-effective analysis while keeping sensitive files for on-premise analysis, thus resolving the contradiction between computational power and data confidentiality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically selects which malware analysis system to use based on file attributes, session characteristics, and system availability. The selection is not static but adapts in real-time, allowing the organization to leverage cloud-based computational power when appropriate while maintaining data confidentiality by switching to on-premise systems when sensitivity requires it.

Inventive Principle:
Principle #15Dynamics

2Loss of information

If on-premise malware analysis system is used, then data confidentiality and privacy are improved, but computational cost and complexity increase

Engineering Contradiction:
Improvedata confidentialityVSAvoidcomputational cost
Core Design Contradiction:
Loss of informationVSPower

Solution Approach 1:

The system segments the malware analysis workload between cloud-based and on-premise systems based on file sensitivity and organizational policy. By dividing the analysis tasks, organizations can maintain on-premise systems for confidential data (preserving data confidentiality) while using cloud systems for non-sensitive files (reducing computational cost and complexity).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a copy of the malware analysis capability in both cloud and on-premise environments. This allows the organization to have redundant analysis capacity available in both locations, enabling them to choose the appropriate system based on the sensitivity of the file being analyzed, thus reducing the burden on any single system and lowering overall computational costs.

Inventive Principle:
Principle #26Copying

3Reliability

If dynamic routing between multiple malware analysis systems is implemented, then security efficacy and resource optimization are improved, but system complexity increases

Engineering Contradiction:
Improvesecurity efficacyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device is designed with multi-functionality, serving as both a network gateway and a malware analysis system selector. It can analyze file attributes, evaluate session characteristics, query multiple malware analysis systems, and make routing decisions all in one place. This universal design consolidates what could be multiple separate systems into one, improving security efficacy while managing system complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where the gateway continuously monitors the status, capacity, and performance of multiple malware analysis systems. Based on this feedback, the gateway dynamically adjusts routing decisions to optimize security efficacy and resource utilization. The feedback loop enables adaptive decision-making that improves reliability without requiring overly complex manual configuration.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10795998B2Dynamic routing of files to a malware analysis system
Publication Date: 2020.10.06 CISCO TECHNOLOGY INC
  • US10795998B2 patent drawing
  • US10795998B2 patent drawing
  • US10795998B2 patent drawing

AI summary

A method for selecting either a first malware analysis system or a second malware analysis system to analyze a file is disclosed. The method includes obtaining, at a network security element, a file sent between a first device and a second device, the file having one or more associated attributes; analyzing, at the network security element, the one or more attributes of the file; selecting, based on the analyzing, either the first malware analysis system or the second malware analysis system as a selected malware analysis system for malware analysis of the file; and providing the file to the selected malware analysis system.