Network Device Proactive Alerting for Unknown Malicious Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security systems are slow to detect and respond to malicious codes, allowing attacks to cause significant damage before patches can be released, and users often refrain from installing antivirus software due to its burden, making devices more vulnerable.
Innovation Solution
A method and system that proactively alerts on unknown malicious codes by a network device receiving file requests, recording source paths, judging executable files, and sending alerts to a monitoring device, which then confirms maliciousness and provides Botnet topology information, allowing for early detection and interception of threats without requiring software installation on terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If antivirus software is installed on terminals for real-time detection, then detection capability is improved, but user convenience deteriorates due to installation burden and system resource consumption
Solution Approach 1:
The patent introduces a network device as an intermediary between terminals and malicious codes. The network device performs detection and analysis of downloaded files, acting as a mediator that protects terminals without requiring antivirus software installation on user devices. This resolves the contradiction by shifting the detection burden from terminals to network infrastructure.
Solution Approach 2:
The detection function is extracted from terminals and relocated to network devices. By taking out the antivirus capability from end-user devices and placing it in network infrastructure, the patent eliminates installation requirements while maintaining detection effectiveness.
2Measurement precision
If vendors wait to obtain malicious code samples after attacks occur, then analysis accuracy is improved, but response time deteriorates causing huge damages
Solution Approach 1:
The patent implements preliminary action by detecting and analyzing malicious codes at the network level before they can execute attacks on terminals. The network device proactively identifies suspicious files during download, preventing attacks before they occur and enabling early vendor response with accurate sample data.
Solution Approach 2:
The system establishes feedback loops where network devices continuously monitor and report malicious code patterns to vendors in real-time. This feedback mechanism provides vendors with timely, accurate sample data for analysis, improving both response time and accuracy simultaneously.
3Reliability
If comprehensive file detection is performed on all downloaded files, then security coverage is improved, but network device complexity increases
Solution Approach 1:
The patent applies local quality by performing different levels of detection on different files based on risk assessment. Instead of uniform comprehensive analysis on all files, the system applies targeted detection strategies - more intensive analysis for executable files and less intensive for other file types, optimizing the balance between security coverage and device complexity.
Data Source
AI summary
A method, a device, and a system for alerting against unknown malicious codes includes judging whether any suspicious code exists in the packet, recording a source path of the suspicious code and sending alert information that carries the source path to a monitoring device. The embodiments of the present disclosure report the source paths of suspicious codes proactively at the earliest possible time, which lays a foundation for shortening the time required for overcoming virus threats, and avoids the trouble of installing software on the terminal.


