Malicious Code Containment via Rate Limiting and Leap-Ahead Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods are inadequate in effectively containing the propagation of various types of malicious code, such as worms, in computer networks, as they fail to completely prevent worms from reaching full saturation potential due to diverse infection strategies.

Innovation Solution

Implementing a dual defense strategy that combines resource-limiting techniques to slow worm propagation and leap-ahead methods for cooperative information sharing to prevent network saturation, including connection rate limiting and peer-based information sharing to coordinate defensive actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If resource-limiting techniques are implemented to slow worm propagation, then the spread of malicious code is reduced, but the network response time and detection speed may be delayed

Engineering Contradiction:
Improveworm propagation speedVSAvoiddetection and response time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring rate limiting policies and detection rules before worm outbreaks occur. Network boundaries and resource limits are established in advance, enabling rapid response when worms are detected without needing to configure defenses during an active outbreak.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A centralized coordinator acts as an intermediary between detection mechanisms and rate limiting enforcement. The coordinator receives worm detection information from various network points and distributes rate limiting commands to boundary devices, enabling coordinated response across the network without direct peer-to-peer communication delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If connection rate limiting is applied to slow down worm spread, then malicious code propagation is reduced, but legitimate network traffic may be constrained

Engineering Contradiction:
Improvemalicious code spreadVSAvoidnetwork traffic flow
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The rate limiting parameters are dynamic rather than static. The system adjusts connection rates based on real-time network conditions, worm detection status, and traffic patterns. When no worm is detected, normal traffic flows unrestricted; when worms are detected, rate limiting is applied selectively to suspicious traffic while maintaining normal operation for legitimate connections.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the coordinator continuously monitors network traffic patterns and worm detection status, then adjusts rate limiting policies accordingly. Traffic analysis feedback helps distinguish between legitimate high-volume traffic and worm-induced traffic, enabling selective rate limiting that protects against worms while maintaining productivity for normal operations.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If leap-ahead techniques with cooperative information sharing are implemented, then network saturation is prevented, but system complexity and coordination overhead increase

Engineering Contradiction:
Improvenetwork saturationVSAvoidcoordination system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The network is segmented into multiple domains, each with its own boundary device and detection capabilities. Each domain operates semi-independently, sharing worm detection information through the centralized coordinator. This segmentation reduces the complexity of coordinating across the entire network by breaking it into manageable domain-level units that can make local decisions based on shared intelligence.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If multiple defense strategies are integrated to combat diverse worm types, then detection capability is improved, but false alarm rate increases

Engineering Contradiction:
Improveworm detection accuracyVSAvoidfalse alarm rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system uses feedback from multiple detection points and traffic analysis to validate worm detections before triggering rate limiting actions. The coordinator aggregates information from various sources and applies decision logic that considers multiple indicators simultaneously, reducing false alarms while maintaining high detection accuracy for actual worm outbreaks.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Detection sensitivity and rate limiting thresholds are dynamically adjusted based on learned traffic patterns and historical data. The system adapts to normal network variations that might otherwise trigger false alarms, while maintaining sensitivity to actual worm behavior patterns. This dynamic adaptation improves reliability by reducing false positives without compromising detection capability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8214901B2Method and apparatus for combating malicious code
Publication Date: 2012.07.03 SRI INTERNATIONAL
  • US8214901B2 patent drawing
  • US8214901B2 patent drawing
  • US8214901B2 patent drawing

AI summary

A method and apparatus are provided for combating malicious code. In one embodiment, a method for combating malicious code in a network includes implementing a resource-limiting technique to slow a propagation of the malicious code and implementing a leap-ahead technique in parallel with the resource-limiting technique to defend against the malicious code reaching a full saturation potential in the network.