Malware Protocol Interception for Automated Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies are limited in identifying and removing malicious software, and they do not effectively gather information about malicious activity to prevent new attacks, as they typically require user intervention and are not capable of intercepting and remediating compromised systems.

Innovation Solution

A computerized system and method that intercepts network communications from compromised computers, determines the protocol used, and sends instructions to remediate malicious activity or gather information by implementing a protocol to connect with the compromised device, allowing for the removal of malware and gathering of malicious activity data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security technologies (anti-virus software, intrusion detection systems, firewalls) are used to protect computers from malware, then basic security protection is provided, but these technologies cannot effectively identify and remove malicious software, cannot automatically gather information about malicious activity, and require user intervention

Engineering Contradiction:
Improveeffectiveness of malware protectionVSAvoidautomated remediation capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent introduces a protocol implementation component as an intermediary between the network communication component and the remediation system. This intermediary automatically implements the detected protocol to establish communication with the compromised device, enabling automated information gathering and remediation without requiring user intervention. The intermediary bridges the gap between detection and action, resolving the contradiction between basic protection and automated remediation capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If security technologies block malicious network communications, then some malicious activity is prevented, but they cannot intercept communications to gather information or perform remediation actions

Engineering Contradiction:
Improvemalicious activity preventionVSAvoidinformation about malicious activity
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

Instead of blocking malicious communications outright, the patent inverts the approach by implementing the malicious protocol to intercept and communicate with the compromised device. The system adopts the malware's communication method to establish contact, then uses this connection to gather information and deliver remediation instructions. This inversion allows information gathering while preventing harmful actions, resolving the contradiction between blocking and information collection.

Inventive Principle:
Principle #13The other way round (Inversion)

3Adaptability or versatility

If malware uses domain name resolution through DNS to maintain connection with attackers, then attackers can control infected computers, but this creates opportunities for protocol analysis and interception

Engineering Contradiction:
Improvemalware communication flexibilityVSAvoidprotocol identification complexity
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary protocol identification and analysis before attempting remediation. The system analyzes incoming network communications to detect and identify the protocol being used by the malware prior to establishing any remediation connection. This preliminary action of protocol detection and classification enables the system to adapt to different malware communication methods, resolving the contradiction between malware adaptability and detection difficulty by preparing the appropriate response in advance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10432658B2Systems and methods for identifying and performing an action in response to identified malicious network traffic
Publication Date: 2019.10.01 WATCHGUARD
  • US10432658B2 patent drawing
  • US10432658B2 patent drawing
  • US10432658B2 patent drawing

AI summary

Computer-implemented systems, methods, and computer-readable media are provided for causing an action to be performed in response to a network communication, such as a malicious network communication. In accordance with some embodiments, a first network communication sent from a client device is received, and a protocol used in the first network communication is determined. Once the protocol is determined, the protocol may be implemented to enable a second network communication with the client device. An action to be performed based at least in part on the protocol may be identified, and an instruction may be sent to the client device in the second network communication.