Ensemble AI Network Monitoring for Proactive Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection systems in the financial and banking sectors lack proactive measures to detect suspicious network activity in real-time, often requiring significant manual intervention and resulting in delayed alerts, which can lead to compliance issues and reputational damage.

Innovation Solution

A multi-level, ensemble network monitoring system utilizing bidirectional long short-term memory (BDLSTM) recurrent neural networks (RNNs) and natural language processing (NLP) to predict potential security threats and initiate remedial measures, such as blocking high-risk user computing devices from accessing private communication networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual human intervention is used to monitor and detect suspicious activity, then detection accuracy can be maintained, but response time is significantly delayed and productivity is reduced

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by training multiple AI detection models (including BDLSTM RNNs and NLP processors) in advance to recognize patterns of suspicious activity. These pre-trained models automatically analyze network traffic in real-time without requiring manual intervention, thereby maintaining high detection accuracy while eliminating response delays associated with human review.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary automated detection system that sits between the network traffic and human operators. This intermediary layer uses ensemble AI models to pre-screen and analyze suspicious activities, only escalating confirmed threats to human operators. This mediation maintains detection accuracy while dramatically reducing the time loss by handling routine analysis automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If perimeter layer controls with manual intervention are implemented, then security monitoring can be performed, but the system lacks proactive warning capabilities and requires significant human resources

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidproactive warning capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system performs preliminary security assessments by having multiple AI models (BDLSTM RNNs, NLP processors, and other detection algorithms) pre-analyze network traffic patterns before threats fully materialize. This preliminary automated analysis enables proactive warnings to be issued to users and administrators before malicious activities complete their execution, eliminating the need for reactive manual intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service security monitoring where the automated ensemble AI system independently performs detection, analysis, and warning functions without requiring human operators. The system serves itself by automatically training on new data, adapting to emerging threats, and generating real-time alerts, thereby achieving high security monitoring capability with minimal human resource requirements.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive parameters about network activity are captured, then better analysis and user awareness can be achieved, but data storage requirements and system complexity increase

Engineering Contradiction:
Improveactivity parameter captureVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the comprehensive parameter capture task across multiple specialized AI models, each responsible for specific types of analysis. BDLSTM RNNs handle temporal pattern recognition, NLP processors analyze text-based indicators, and other models focus on specific threat vectors. This segmentation allows the system to capture comprehensive parameters with high measurement precision while distributing system complexity across modular, independently manageable components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The ensemble AI system achieves multi-functionality by using a unified architecture that processes diverse network activity parameters through multiple specialized models. This universal system handles various threat types (malware, phishing, ransomware) and data formats simultaneously, capturing comprehensive parameters without proportionally increasing overall system complexity through shared infrastructure and coordinated analysis.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12021895B2Malware detection with multi-level, ensemble artificial intelligence using bidirectional long short-term memory recurrent neural networks and natural language processing
Publication Date: 2024.06.25 BANK OF AMERICA CORP
  • US12021895B2 patent drawing
  • US12021895B2 patent drawing
  • US12021895B2 patent drawing

AI summary

A multi-level, ensemble network monitoring system for detection of suspicious network activity from one or more a plurality of user computing devices on an external network communicatively connected via a network server to a private communication network is disclosed. In malware detection, the ensemble network monitoring system comprises artificial intelligence (AI) with bidirectional long short-term memory (BDLSTM) recurrent neural networks (RNNs) and natural language processing (NLP) to predict possible security threats and then initiate remedial measures accordingly. Enabling a proactive approach to detection and prevention of potential malicious activity, the BDLSTM RNN may perform real-time monitoring and proactively forecast network security violations to block network communications associated with high-risk user computing devices from accessing a private communication network.