Network Data Quarantine for Malware Containment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for containing malware, such as worms and viruses, are inadequate as they often rely on outdated antivirus applications and signature files, which can fail to detect new threats, and require manual installation of updates on each device, leading to potential network compromise.

Innovation Solution

Implementing a system that quarantines network data from digital devices upon connection to a communication network, using a controller to analyze data for malware and activate security programs to identify risks, update security settings, and generate unauthorized activity signatures, thereby containing malware without the need for agents on each device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus applications and signature files are used to detect malware, then detection capability is improved, but the system becomes vulnerable to new threats and requires manual updates on each device

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidresponse to new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary security analysis by quarantining network data from newly connected devices before they can access the network. Security programs are activated in advance to scan and analyze the quarantined data, updating security measures before potential threats can spread. This preliminary action ensures that new threats are detected and neutralized before they can compromise the network, eliminating the need for manual updates on each device.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual updates are installed on each device, then security measures are kept current, but the complexity and time required for maintenance increases

Engineering Contradiction:
Improvesecurity measure currencyVSAvoidmaintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service security maintenance through automated analysis of quarantined network data. When new devices connect, their network data is automatically quarantined and analyzed by security programs without requiring manual intervention. The system self-updates security measures by analyzing detected threats and generating updated security signatures, eliminating the need for IT staff to manually update each device and significantly reducing maintenance time.

Inventive Principle:
Principle #25Self-service

3Speed

If network data is monitored and analyzed in real-time, then malware detection speed is improved, but the system complexity and resource requirements increase

Engineering Contradiction:
Improvemalware detection speedVSAvoidsystem architecture complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system segments network monitoring by creating a quarantine zone that separates newly connected devices from the main network. Network data from new devices is routed to a dedicated analysis environment where security programs perform real-time scanning. This segmentation allows rapid detection of threats in isolated segments without requiring complex real-time monitoring of the entire network, reducing overall system complexity while maintaining fast detection speeds.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8539582B1Malware containment and security analysis on connection
Publication Date: 2013.09.17 MAGENTA SECURITY HOLDINGS LLC
  • US8539582B1 patent drawing
  • US8539582B1 patent drawing
  • US8539582B1 patent drawing

AI summary

Systems and methods for malware containment and security analysis on connection are provided. Digital devices are quarantined for a predetermined period of time upon connection to the communication network. When a digital device is quarantined, all network data transmitted by the digital device is directed to a controller which then analyzes the network data to identify unauthorized activity and/or malware within the newly connected digital device. An exemplary method to contain malware includes detecting a digital device upon connection with a communication network, quarantining network data from the digital device for a predetermined period of time, transmitting a command to the digital device to activate a security program to identify security risks, and analyzing the network data to identify malware within the digital device.