Malicious Communication Detection System Using Indicator Packages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of electronic communications has led to an increase in malicious communications that are difficult to detect and mitigate in real-time across multiple computer terminals, posing threats to data security and system functionality.
Innovation Solution
A computerized system configured to analyze electronic communications for malicious attachments, URLs, and indicators of compromise, constructing indicator packages for threat prevention systems, and transmitting these indicators to networked devices to enhance threat defense, while also simulating malicious communications for user training and transmitting threat trigger signals to third-party provider systems for real-time blocking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional security systems are used to detect malicious communications, then system complexity is reduced, but detection capability and response time deteriorate
Solution Approach 1:
The security system is divided into multiple specialized modules: communication interceptor for capturing communications, analyzer for examining communications and extracting indicators, database for storing indicators, and threat prevention system for blocking threats. Each module performs a specific function, improving detection capability while managing complexity through functional segmentation.
Solution Approach 2:
The patent introduces indicator packages as intermediary data structures that bridge the gap between communication analysis and threat prevention. These standardized packages containing indicators of compromise (IOCs) enable efficient information exchange between modules and external systems, improving detection precision without proportionally increasing system complexity.
2Speed
If real-time analysis of all electronic communications is performed, then detection speed is improved, but processing load and resource consumption increase
Solution Approach 1:
The system performs preliminary extraction of indicators of compromise from communications during the analysis phase, storing these indicators in advance in the database. This preliminary action enables the threat prevention system to quickly compare incoming communications against known indicators without performing full analysis in real-time, reducing processing load while maintaining fast response times.
Solution Approach 2:
The analyzer extracts specific indicators of compromise (such as malicious URLs, email addresses, file hashes) from communications and separates them into standardized indicator packages. This extraction approach focuses processing on identifying key threat indicators rather than analyzing entire communications, significantly reducing processing load while maintaining detection speed.
3Adaptability or versatility
If comprehensive threat indicators are collected and distributed across multiple devices, then protection coverage is improved, but communication overhead and data transmission increase
Solution Approach 1:
Each networked device maintains its own threat prevention system with locally stored indicator packages. This local quality approach allows each device to independently block threats using indicators relevant to its specific context, improving protection coverage across the network without requiring constant centralized communication. Devices receive indicator packages from the security system and apply them locally.
4Measurement precision
If multiple analysis methods are applied to each communication, then detection accuracy is improved, but processing time and system complexity increase
Solution Approach 1:
The analyzer dynamically selects and applies analysis methods based on the characteristics of each communication and the current threat landscape. Rather than applying all possible analysis methods uniformly to every communication, the system adapts its analysis approach, applying more comprehensive methods only when necessary, thereby improving detection accuracy while minimizing processing time.
Data Source
AI summary
Embodiments of the present invention relate to, in general, detecting and mitigating malicious communications. Typically, a system of the present invention is configured to deliver indicators of compromise in response to identifying and isolating malicious communication. Moreover, the system is configured to analyze an electronic communication to determine if it is malicious or if it has a malicious payload. In some embodiments, the system is configured to determine an indicator of compromise for the electronic communication determined to be malicious, and transmit this indicator of compromise to the first networked device. In some embodiments, the system transmits a threat trigger signal to a third party provider. The threat trigger signal is configured to allow an application or system provided by the third party provider to block a threat caused by the electronic communication. In some embodiments, the system provides training to help users better identify and report threats.


