Network Resource Reputation Scoring for Malicious Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting malicious resources in networks are ineffective in identifying modified virus codes and targeted attacks, as they rely on signature-based scanning or behavior monitoring, which can lead to false positives and miss newly developed threats, and require frequent updates to signature lists.
Innovation Solution
A system that monitors communication between network resources using a monitoring unit to assign reputation scores based on compliance with policies, consolidating scores over time to classify resources as potentially malicious, with a graphical user interface for policy customization and reputation display.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If signature-based scanning is used to detect malicious resources, then detection of known threats is improved, but detection of modified virus codes and targeted attacks deteriorates
Solution Approach 1:
The patent segments the detection process into multiple independent components: signature-based detection, behavior monitoring, and reputation scoring. Each component operates independently and contributes to the overall detection result, allowing the system to maintain strengths of each method while mitigating individual weaknesses.
Solution Approach 2:
The patent creates a composite detection approach by combining multiple detection methods (signature scanning, behavior analysis, reputation scoring) into a unified system. This composite approach leverages the strengths of each method to achieve both high accuracy for known threats and adaptability for new threats.
2Reliability
If behavior monitoring is used to scan for potential intrusions, then detection of risky activities is improved, but false positives and processing overhead increase
Solution Approach 1:
The patent applies local quality by implementing behavior monitoring selectively based on risk levels and contextual factors. Not all resources undergo the same level of scrutiny; instead, monitoring intensity is adjusted locally based on observed behavior patterns, reducing overall processing overhead while maintaining detection reliability.
Solution Approach 2:
The patent dynamically adjusts monitoring parameters such as threshold values and scoring weights based on observed behavior patterns and threat levels. This allows the system to optimize between detection sensitivity and processing overhead by changing parameters rather than maintaining fixed monitoring intensity.
3Adaptability or versatility
If signature lists are frequently updated to catch new threats, then detection of new threats is improved, but system maintenance complexity and time lag increase
Solution Approach 1:
The patent implements preliminary action by maintaining a reputation database that pre-evaluates resources before they become active threats. By continuously monitoring and scoring resources in advance, the system prepares detection data ahead of time, reducing the time lag when new threats emerge.
Solution Approach 2:
The patent establishes a feedback loop where detection results and threat intelligence are continuously fed back into the reputation scoring system. This feedback mechanism automatically updates the system's knowledge base, reducing reliance on manual signature updates and minimizing detection time lags.
Data Source
AI summary
Systems and methods for detecting malicious resources by analyzing communication between multiple resources coupled to a network are provided. According to one embodiment, a method of client reputation monitoring is provided. A monitoring unit executing on a network security device operable to protect a private network observes activities relating to multiple monitored devices within the private network. For each of the observed activities, a score is assigned by the monitoring unit based upon a policy of multiple polices established within the monitoring unit. For each of the monitored devices, a current reputation score is maintained by the monitoring unit based upon the score and a historical score associated with the monitored device. A monitored is classified by the monitoring unit as potentially being a malicious resource based upon the current reputation score for the monitored device.


