Network Controller Malware Containment via Data Redirection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for containing malware, such as worms and viruses, are inadequate as they often fail to detect and prevent infections, especially when computers reconnect to networks, leading to potential network compromises and data breaches.
Innovation Solution
Implementing a system that temporarily redirects network data from newly connected digital devices to a controller for analysis, using techniques like ARP manipulation and virtual machine analysis to detect and isolate malware, and generating unauthorized activity signatures for corrective actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anti-virus applications and firewall applications are installed on network servers and routers, then network security is improved, but the system complexity and maintenance burden increase
Solution Approach 1:
The patent introduces a network controller as an intermediary device that centralizes malware detection and containment functions. Instead of distributing anti-virus and firewall applications across multiple network servers and routers, the controller acts as a mediator that intercepts, analyzes, and manages security operations centrally, thereby reducing system complexity while maintaining security.
Solution Approach 2:
The patent extracts malware detection and containment functions from individual network devices and consolidates them into a dedicated network controller. By taking out these security functions from the distributed system and placing them in a centralized controller, the complexity of each network device is reduced while the overall security capability is maintained or enhanced.
2Measurement precision
If anti-virus applications are updated frequently to detect new worms and viruses, then detection capability is improved, but the time and resources required for maintenance increase
Solution Approach 1:
The patent implements preliminary action by proactively containing potentially malicious devices upon connection to the network, before malware can propagate. The network controller automatically isolates suspicious devices in a containment mode and begins analysis, so that when malware signatures are updated or new threats are detected, the damage has already been prevented and the devices are already under control, reducing the need for frequent maintenance interventions.
Solution Approach 2:
The patent establishes a feedback mechanism where the network controller continuously monitors network traffic, analyzes device behavior, and automatically updates containment decisions based on detected patterns. This closed-loop system provides real-time feedback on malware activity and automatically adjusts security measures, reducing the need for manual updates and maintenance while maintaining high detection capability.
3Speed
If network data from newly connected devices is analyzed in real-time, then malware detection speed is improved, but the processing load and system resources increase
Solution Approach 1:
The patent applies partial action by implementing automatic containment for all newly connected devices, which is a simpler and less resource-intensive operation than full real-time analysis. The controller quickly isolates devices based on connection detection, then performs gradual analysis of contained devices. This approach achieves fast initial response (containment) without the immediate burden of full real-time analysis, balancing speed and resource consumption.
Data Source
AI summary
Systems and methods for malware containment on connection are provided. Digital devices are quarantined for a predetermined period of time upon connection to the communication network. When a digital device is quarantined, all network data transmitted by the digital device is temporarily directed to a controller which then analyzes the network data to identify unauthorized activity and/or malware within the newly connected digital device. An exemplary method to contain malware comprises detecting a digital device upon connection with a communication network, temporarily redirecting network data from the digital device for a predetermined period of time, and analyzing the network data to identify malware within the digital device.


