Multi-layer Malware Detection Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting malware, especially repackaged versions, are ineffective due to their reliance on pattern matching and deep packet inspection, which can miss hidden or obfuscated malicious code, leading to logistical challenges in organizing and presenting vast amounts of malware threat data.

Innovation Solution

A system comprising multiple layers of anti-malware testing, where data from different sources is evaluated to identify malware types and visualize their spread, allowing for continuous updates and improved detection methods that do not solely depend on content analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional pattern matching and deep packet inspection methods are used to detect malware, then the detection process is simple and fast, but the detection reliability deteriorates because repackaged and obfuscated malware can evade detection

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection system is segmented into multiple independent test layers (first test layer, second test layer, etc.), each performing specific anti-malware tests. This segmentation allows the system to handle complex detection tasks by dividing them into manageable components, improving reliability without overwhelming complexity in a single detection mechanism

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to malware detection by creating visualizations that map malware spread across network locations. This dimensional transformation from raw data to visual representations enables better detection and understanding of malware patterns that conventional packet inspection cannot capture

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multiple layers of anti-malware testing are implemented to improve detection reliability, then the detection capability improves, but the device complexity and data processing burden increase

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts and processes only the necessary test data from each layer, separating useful information about malware types and spread patterns from the bulk of network traffic. This extraction approach maintains high detection reliability while reducing the processing burden on individual components

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates visual representations (copies) of malware spread patterns and test results, allowing the system to analyze and present information without processing every raw data packet in detail. These visual copies enable efficient data processing and presentation while maintaining detection accuracy

Inventive Principle:
Principle #26Copying

3Measurement precision

If vast amounts of malware threat data are collected and analyzed, then the detection accuracy improves, but the ease of operation deteriorates due to logistical challenges in organizing and presenting the data

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddata organization and presentation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system transforms complex, multi-dimensional malware data into visualizations that map malware vectors and types across network locations. This dimensional transformation makes the data more manageable and easier to interpret, maintaining high measurement precision while significantly improving ease of operation

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent uses visualizations with color-coded representations to differentiate and highlight various malware types and their spread patterns. This color-coding approach organizes complex data intuitively, allowing users to quickly identify and operate with specific malware threats without processing raw data complexity

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS20250039191A1Visualization tool for real-time network risk assessment
Publication Date: 2025.01.30 SONICWALL INC
  • US20250039191A1 patent drawing
  • US20250039191A1 patent drawing
  • US20250039191A1 patent drawing

AI summary

The present disclosure relates to methods and apparatus that collect data regarding malware threats, that organizes this collected malware threat data, and that provides this data to computers or people such that damage associated with these software threats can be quantified and reduced. The present disclosure is also directed to preventing the spread of malware before that malware can damage computers or steal computer data. Methods consistent with the present disclosure may optimize tests performed at different levels of a multi-level threat detection and prevention system. As such, methods consistent with the present disclosure may collect data from various sources that may include endpoint computing devices, firewalls/gateways, or isolated (e.g. “sandbox”) computers. Once this information is collected, it may then be organized, displayed, and analyzed in ways that were not previously possible.