Malware Detection Appliance Delay Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware detection systems often fail to prevent infection at network nodes and allow lateral movement of malware within networks, as they detect malware after damage has occurred, and existing security measures are inadequate to intercept and analyze malicious content in real-time.

Innovation Solution

A malware detection system (MDS) appliance that injects delay into the delivery and processing of communication traffic at endpoints to allow for extensive malware detection analysis, using a threat-aware microvisor and virtualization architecture to intercept and analyze network packets, and injects delay through manipulation of the TCP protocol to ensure thorough analysis before allowing traffic to proceed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If malware detection analysis is performed extensively at the appliance, then detection precision is improved, but processing time increases

Engineering Contradiction:
Improvemalware detection precisionVSAvoidcontent processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary malware detection analysis before allowing content to proceed to the endpoint. By conducting the analysis in advance at the appliance and only allowing delayed content through once validation is complete, the system achieves thorough malware detection without impacting the user's perceived processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The appliance acts as an intermediary between the content source and the endpoint. It intercepts content, performs extensive malware detection analysis, and then either allows the content through or blocks it. This intermediary role enables comprehensive security checking without requiring the endpoint to perform time-consuming analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security analysis is performed on all incoming traffic, then reliability of malware detection is improved, but productivity of network traffic flow deteriorates

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoidnetwork traffic throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements selective skipping where content that passes initial malware detection checks is rushed through to the endpoint without additional delay. Only content that fails the malware detection analysis is subjected to extended inspection, allowing most legitimate traffic to flow freely while maintaining security for suspicious content.

Inventive Principle:
Principle #21Skipping (Rushing through)

Solution Approach 2:

The system performs partial malware detection analysis on all traffic and excessive (extended) analysis only on suspicious content. This partial/excessive approach ensures that normal traffic experiences minimal disruption while suspicious traffic receives the thorough analysis needed for reliable malware detection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9912681B1Injection of content processing delay in an endpoint
Publication Date: 2018.03.06 MAGENTA SECURITY HOLDINGS LLC
  • US9912681B1 patent drawing
  • US9912681B1 patent drawing
  • US9912681B1 patent drawing

AI summary

A malware detection system (MDS) appliance is configured to inject delay associated with delivery and/or processing of communication traffic directed to one or more endpoints in a network. The appliance may be positioned within the network to intercept and analyze (e.g., replay and instrument) one or more network packets of the communication traffic to detect whether an object of the packet contains malware. However, such analysis, e.g., malware detection analysis, may require extensive processing at the appliance and, thus, consume a considerable amount of time. Accordingly, the MDS appliance may inject delay into the delivery and/or processing of the object on the endpoint until the malware detection analysis completes and the malware is validated.