Multi-Flow Object Analysis for Malicious Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security appliances fail to effectively detect malicious attacks by analyzing the characteristics of multiple related flows due to limitations in static analysis, leading to false negatives.

Innovation Solution

A threat detection and prevention system that aggregates multiple related flows into a multi-flow object, conducts static analysis to identify suspicious characteristics, and triggers enhanced static or dynamic analysis based on feedback signaling to verify potential malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional security appliances conduct static analysis of a single flow, then the analysis process is simple and fast, but the detection accuracy is low leading to false negatives

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple related flows into a single multi-flow object for comprehensive analysis. The system aggregates packets from multiple flows that share common characteristics (source IP, destination IP, protocol type) and analyzes them together as one unified object, enabling detection of attack patterns that span across multiple flows while maintaining manageable analysis complexity through structured aggregation

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If conventional security appliances analyze single flow characteristics, then the processing speed is fast, but the ability to detect malicious attacks spanning multiple flows is insufficient

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-aggregating packets into multi-flow objects and pre-calculating flow characteristics before actual threat detection is needed. This preparation work includes collecting packets from multiple flows, identifying their relationships, and organizing them into structured multi-flow objects, so that when analysis is triggered, the system can quickly evaluate pre-processed data rather than starting from scratch

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary multi-flow object that acts as a mediator between individual flows and the analysis engine. Instead of analyzing each flow separately or all flows simultaneously, the system creates an intermediate representation that consolidates relevant information from multiple flows, making the detection process more efficient and reliable

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9432389B1System, apparatus and method for detecting a malicious attack based on static analysis of a multi-flow object
Publication Date: 2016.08.30 MAGENTA SECURITY HOLDINGS LLC
  • US9432389B1 patent drawing
  • US9432389B1 patent drawing
  • US9432389B1 patent drawing

AI summary

In an embodiment, a threat detection and prevention system comprises a network-traffic static analysis logic and a classification engine. The network-traffic static analysis logic is configured to conduct an analysis of a multi-flow object by analyzing characteristics of the multi-flow object and determining if the characteristics of the multi-flow object is associated with a malicious attack such as being indicative of an exploit for example. The classification engine is configured to receive results of the analysis of the multi-flow object and, based on the results of the analysis of the multi-flow object, determine whether the multi-flow object is associated with a malicious attack.