Network Intrusion Detection for Malware Source Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online retailers and their customers are at risk of malware and nefarious activities from vendors, which can damage network infrastructure and reputation, as existing security measures may not effectively detect and prevent malware originating from third-party advertisements or services.

Innovation Solution

A network intrusion detection system that collects browsing data from user systems, compares it with data from other users, and identifies the source of malware, allowing for prevention of further malware dissemination from identified sources, including third-party advertisements, and provides users with removal tools and information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If third-party vendors are allowed to provide goods and services on the online retailer's network site, then additional revenue and goods/services are generated, but the risk of malware and nefarious activity increases

Engineering Contradiction:
Improverevenue generationVSAvoidmalware risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

A network intrusion detection application is introduced as an intermediary between third-party vendors and the online retailer's network infrastructure. This application monitors network traffic, detects malware, and prevents malicious activity while allowing legitimate vendor operations to continue, thus maintaining revenue generation while mitigating malware risk

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The intrusion detection application performs preliminary scanning and analysis of network traffic from third-party vendors before malicious content can compromise the system. By detecting and blocking malware proactively rather than reactively, the system prevents harmful effects while maintaining business operations

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security measures are strengthened to detect and prevent malware from third-party sources, then network security is improved, but system complexity and detection difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intrusion detection application autonomously monitors network traffic, automatically detects malware patterns, and implements blocking actions without requiring constant human intervention. The system self-manages the complexity of security monitoring while providing reliable protection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously analyzes network traffic and uses feedback from detected patterns to improve its detection capabilities. By learning from ongoing monitoring data, the system maintains high security reliability without requiring proportional increases in system complexity

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8910284B1Detecting malware
Publication Date: 2014.12.09 AMAZON TECH INC
  • US8910284B1 patent drawing
  • US8910284B1 patent drawing
  • US8910284B1 patent drawing

AI summary

Disclosed are various embodiments for determining a source of malware. At least one embodiment of a method includes receiving browsing data from a plurality of client devices, the data being sent by the plurality of client devices, in response to a determination of malware on the plurality of client devices and determining, from the browsing data, a source for the malware. Further, some embodiments include determining whether the source for the malware is associated with a predetermined network site and in response to determining that the source of the malware is associated with a predetermined network site, preventing download of at least a portion of the predetermined network site.