Network Intrusion Detection for Malware Source Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online retailers and their customers are at risk of malware and nefarious activities from vendors, which can damage network infrastructure and reputation, as existing security measures may not effectively detect and prevent malware originating from third-party advertisements or services.
Innovation Solution
A network intrusion detection system that collects browsing data from user systems, compares it with data from other users, and identifies the source of malware, allowing for prevention of further malware dissemination from identified sources, including third-party advertisements, and provides users with removal tools and information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If third-party vendors are allowed to provide goods and services on the online retailer's network site, then additional revenue and goods/services are generated, but the risk of malware and nefarious activity increases
Solution Approach 1:
A network intrusion detection application is introduced as an intermediary between third-party vendors and the online retailer's network infrastructure. This application monitors network traffic, detects malware, and prevents malicious activity while allowing legitimate vendor operations to continue, thus maintaining revenue generation while mitigating malware risk
Solution Approach 2:
The intrusion detection application performs preliminary scanning and analysis of network traffic from third-party vendors before malicious content can compromise the system. By detecting and blocking malware proactively rather than reactively, the system prevents harmful effects while maintaining business operations
2Reliability
If security measures are strengthened to detect and prevent malware from third-party sources, then network security is improved, but system complexity and detection difficulty increase
Solution Approach 1:
The intrusion detection application autonomously monitors network traffic, automatically detects malware patterns, and implements blocking actions without requiring constant human intervention. The system self-manages the complexity of security monitoring while providing reliable protection
Solution Approach 2:
The system continuously analyzes network traffic and uses feedback from detected patterns to improve its detection capabilities. By learning from ongoing monitoring data, the system maintains high security reliability without requiring proportional increases in system complexity
Data Source
AI summary
Disclosed are various embodiments for determining a source of malware. At least one embodiment of a method includes receiving browsing data from a plurality of client devices, the data being sent by the plurality of client devices, in response to a determination of malware on the plurality of client devices and determining, from the browsing data, a source for the malware. Further, some embodiments include determining whether the source for the malware is associated with a predetermined network site and in response to determining that the source of the malware is associated with a predetermined network site, preventing download of at least a portion of the predetermined network site.


