Network Device Proactive Alerting for Unknown Malicious Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems are slow to detect and respond to malicious codes, allowing attacks to cause significant damage before patches can be released, and users often refrain from installing antivirus software due to its burden, making devices more vulnerable.

Innovation Solution

A method and system that proactively alerts on unknown malicious codes by a network device receiving file requests, recording source paths, judging executable files, and sending alerts to a monitoring device, which then confirms maliciousness and provides Botnet topology information, allowing for early detection and interception of threats without requiring software installation on terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus software is installed on terminals for real-time detection, then detection capability is improved, but user convenience deteriorates due to installation burden and system resource consumption

Engineering Contradiction:
Improvedetection capabilityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a network device as an intermediary between terminals and malicious codes. The network device performs detection and analysis of downloaded files, acting as a mediator that protects terminals without requiring antivirus software installation on user devices. This resolves the contradiction by shifting the detection burden from terminals to network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The detection function is extracted from terminals and relocated to network devices. By taking out the antivirus capability from end-user devices and placing it in network infrastructure, the patent eliminates installation requirements while maintaining detection effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If vendors wait to obtain malicious code samples after attacks occur, then analysis accuracy is improved, but response time deteriorates causing huge damages

Engineering Contradiction:
Improveanalysis accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by detecting and analyzing malicious codes at the network level before they can execute attacks on terminals. The network device proactively identifies suspicious files during download, preventing attacks before they occur and enabling early vendor response with accurate sample data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes feedback loops where network devices continuously monitor and report malicious code patterns to vendors in real-time. This feedback mechanism provides vendors with timely, accurate sample data for analysis, improving both response time and accuracy simultaneously.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive file detection is performed on all downloaded files, then security coverage is improved, but network device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by performing different levels of detection on different files based on risk assessment. Instead of uniform comprehensive analysis on all files, the system applies targeted detection strategies - more intensive analysis for executable files and less intensive for other file types, optimizing the balance between security coverage and device complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10027693B2Method, device and system for alerting against unknown malicious codes within a network environment
Publication Date: 2018.07.17 HUAWEI TECH CO LTD
  • US10027693B2 patent drawing
  • US10027693B2 patent drawing
  • US10027693B2 patent drawing

AI summary

A method, a device, and a system for alerting against unknown malicious codes includes judging whether any suspicious code exists in the packet, recording a source path of the suspicious code and sending alert information that carries the source path to a monitoring device. The embodiments of the present disclosure report the source paths of suspicious codes proactively at the earliest possible time, which lays a foundation for shortening the time required for overcoming virus threats, and avoids the trouble of installing software on the terminal.