Network Resource Reputation Scoring for Malicious Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting malicious resources in networks are ineffective in identifying modified virus codes and targeted attacks, as they rely on signature-based scanning or behavior monitoring, which can lead to false positives and miss newly developed threats, and require frequent updates to signature lists.

Innovation Solution

A system that monitors communication between network resources using a monitoring unit to assign reputation scores based on compliance with policies, consolidating scores over time to classify resources as potentially malicious, with a graphical user interface for policy customization and reputation display.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based scanning is used to detect malicious resources, then detection of known threats is improved, but detection of modified virus codes and targeted attacks deteriorates

Engineering Contradiction:
Improvedetection accuracy for known threatsVSAvoiddetection capability for modified and targeted attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the detection process into multiple independent components: signature-based detection, behavior monitoring, and reputation scoring. Each component operates independently and contributes to the overall detection result, allowing the system to maintain strengths of each method while mitigating individual weaknesses.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite detection approach by combining multiple detection methods (signature scanning, behavior analysis, reputation scoring) into a unified system. This composite approach leverages the strengths of each method to achieve both high accuracy for known threats and adaptability for new threats.

Inventive Principle:
Principle #40Composite materials

2Reliability

If behavior monitoring is used to scan for potential intrusions, then detection of risky activities is improved, but false positives and processing overhead increase

Engineering Contradiction:
Improvedetection of risky activitiesVSAvoidprocessing overhead and false positives
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing behavior monitoring selectively based on risk levels and contextual factors. Not all resources undergo the same level of scrutiny; instead, monitoring intensity is adjusted locally based on observed behavior patterns, reducing overall processing overhead while maintaining detection reliability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically adjusts monitoring parameters such as threshold values and scoring weights based on observed behavior patterns and threat levels. This allows the system to optimize between detection sensitivity and processing overhead by changing parameters rather than maintaining fixed monitoring intensity.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If signature lists are frequently updated to catch new threats, then detection of new threats is improved, but system maintenance complexity and time lag increase

Engineering Contradiction:
Improvedetection of newly developed threatsVSAvoidtime lag between new threats and signature updates
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by maintaining a reputation database that pre-evaluates resources before they become active threats. By continuously monitoring and scoring resources in advance, the system prepares detection data ahead of time, reducing the time lag when new threats emerge.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback loop where detection results and threat intelligence are continuously fed back into the reputation scoring system. This feedback mechanism automatically updates the system's knowledge base, reducing reliance on manual signature updates and minimizing detection time lags.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10009361B2Detecting malicious resources in a network based upon active client reputation monitoring
Publication Date: 2018.06.26 FORTINET INC
  • US10009361B2 patent drawing
  • US10009361B2 patent drawing
  • US10009361B2 patent drawing

AI summary

Systems and methods for detecting malicious resources by analyzing communication between multiple resources coupled to a network are provided. According to one embodiment, a method of client reputation monitoring is provided. A monitoring unit executing on a network security device operable to protect a private network observes activities relating to multiple monitored devices within the private network. For each of the observed activities, a score is assigned by the monitoring unit based upon a policy of multiple polices established within the monitoring unit. For each of the monitored devices, a current reputation score is maintained by the monitoring unit based upon the score and a historical score associated with the monitored device. A monitored is classified by the monitoring unit as potentially being a malicious resource based upon the current reputation score for the monitored device.