Multi-Flow Object Analysis for Malicious Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security appliances fail to effectively detect malicious attacks by analyzing the characteristics of multiple related flows due to limitations in static analysis, leading to false negatives.
Innovation Solution
A threat detection and prevention system that aggregates multiple related flows into a multi-flow object, conducts static analysis to identify suspicious characteristics, and triggers enhanced static or dynamic analysis based on feedback signaling to verify potential malicious activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional security appliances conduct static analysis of a single flow, then the analysis process is simple and fast, but the detection accuracy is low leading to false negatives
Solution Approach 1:
The patent merges multiple related flows into a single multi-flow object for comprehensive analysis. The system aggregates packets from multiple flows that share common characteristics (source IP, destination IP, protocol type) and analyzes them together as one unified object, enabling detection of attack patterns that span across multiple flows while maintaining manageable analysis complexity through structured aggregation
2Reliability
If conventional security appliances analyze single flow characteristics, then the processing speed is fast, but the ability to detect malicious attacks spanning multiple flows is insufficient
Solution Approach 1:
The system performs preliminary actions by pre-aggregating packets into multi-flow objects and pre-calculating flow characteristics before actual threat detection is needed. This preparation work includes collecting packets from multiple flows, identifying their relationships, and organizing them into structured multi-flow objects, so that when analysis is triggered, the system can quickly evaluate pre-processed data rather than starting from scratch
Solution Approach 2:
The patent introduces an intermediary multi-flow object that acts as a mediator between individual flows and the analysis engine. Instead of analyzing each flow separately or all flows simultaneously, the system creates an intermediate representation that consolidates relevant information from multiple flows, making the detection process more efficient and reliable
Data Source
AI summary
In an embodiment, a threat detection and prevention system comprises a network-traffic static analysis logic and a classification engine. The network-traffic static analysis logic is configured to conduct an analysis of a multi-flow object by analyzing characteristics of the multi-flow object and determining if the characteristics of the multi-flow object is associated with a malicious attack such as being indicative of an exploit for example. The classification engine is configured to receive results of the analysis of the multi-flow object and, based on the results of the analysis of the multi-flow object, determine whether the multi-flow object is associated with a malicious attack.


