Network-wide malware mapping for root cause detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions face challenges in distinguishing malicious computing activity from benign processes in real-time, leading to potential network damage before malware can be identified, and they struggle to roll back sophisticated malicious activities across complex network environments.

Innovation Solution

A network management system that detects malicious activities, determines the malware root, and generates a network-wide malware mapping to visualize and rollback malicious activities across endpoints, cloud services, and public clouds, enabling retrospective revocation of all malicious actions with agentless quarantine capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time detection of malicious activities is implemented, then network security is improved, but false positives from benign processes increase

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system performs preliminary actions by detecting and mapping malicious activities before they can cause extensive damage. The network management system continuously monitors network traffic and device behaviors, identifying malware root causes and their spawned malicious activities across the network, enabling preventive rollback before significant harm occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by generating comprehensive malware mappings that show hierarchical relationships between malware roots and their spawned malicious activities. This feedback loop allows the system to learn from detected patterns, improve detection accuracy, and adjust security responses based on the evolving threat landscape while reducing false positives.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive malware mapping across entire network is generated, then malware root identification is improved, but system complexity increases

Engineering Contradiction:
Improvemalware root identificationVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex network monitoring task by focusing on identifying the malware root cause and mapping its hierarchical relationships with spawned malicious activities. Rather than attempting to analyze every single network event in detail, the system segments the problem into identifying the origin point and tracing its propagation path, simplifying the overall analysis complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network management system acts as an intermediary that consolidates and processes security information from multiple devices and sources. It generates a unified malware mapping that mediates between complex raw data from various network devices and the security analysts, presenting a simplified hierarchical view of malware relationships and reducing the complexity of manual analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If retrospective rollback of malicious activities is implemented, then network damage reduction is improved, but detection time increases

Engineering Contradiction:
Improvenetwork damageVSAvoiddetection time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system performs preliminary mapping of malicious activities and their hierarchical relationships in advance, maintaining ready-to-execute rollback capabilities. When malware is detected, the pre-established malware mapping allows for immediate retrospective rollback of malicious activities without requiring time-consuming analysis, thus reducing both detection time and network damage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables rushing through the detection and response process by maintaining pre-computed malware mappings that can be quickly applied for rollback. The hierarchical mapping structure allows security operations to skip lengthy analysis phases and directly implement rollback actions based on pre-identified malware roots and their associated malicious activities, significantly reducing response time.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11689560B2Network-wide malware mapping
Publication Date: 2023.06.27 CISCO TECHNOLOGY INC
  • US11689560B2 patent drawing
  • US11689560B2 patent drawing
  • US11689560B2 patent drawing

AI summary

A network management system is configured to detect one or more malicious activities at one or more devices connected to a network. The network management system is configured to determine a malware root of the one or more malicious activities and generate a network-wide indicating a hierarchical relationship between the malicious activities spawned by the malware root and the malware root. The malicious activities spawned by the malware root represented in the network-wide malware include the one or more malicious activities and include a plurality of malicious activities spawned across a plurality of devices connected to the network.