Network Security System with On-Demand Forensics Agent
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems, such as firewalls and endpoint detection and response (EDR), are inefficient in identifying and responding to malicious activities on networks, as they require substantial resources for constant monitoring and data collection, and lack specialized responses to specific threats, often losing critical information and failing to effectively defend against attacks.
Innovation Solution
A method and system that monitors network communications, detects suspect activities, suspends communication, deploys a forensics software agent to collect and analyze data, and determines a response action based on the analysis, using a policy management unit to select and execute appropriate actions such as terminating processes or isolating files, thereby addressing the inefficiencies of existing systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a firewall or EDR is used to monitor network communications, then network security is improved, but resource consumption increases substantially
Solution Approach 1:
The system segments the security monitoring function into two parts: a lightweight firewall/EDR component that runs continuously with minimal resource usage, and a forensics software agent that is deployed only when suspect activity is detected. This segmentation allows the system to maintain security while reducing overall resource consumption by avoiding constant operation of heavy monitoring components.
Solution Approach 2:
The system performs preliminary monitoring with the lightweight firewall/EDR to detect suspect network communications before deploying the full forensics software agent. This preliminary action allows the system to identify potential threats and only then activate the more resource-intensive analysis tools, optimizing resource usage while maintaining security.
2Measurement precision
If constant monitoring and data collection is performed, then detection capability is improved, but resource consumption increases
Solution Approach 1:
Instead of constant monitoring, the system uses periodic action by having the lightweight firewall/EDR monitor network communications and only triggering the full forensics software agent when suspect activity is detected. This periodic activation of the heavy-duty detection tools maintains detection capability while significantly reducing resource consumption compared to continuous operation.
Solution Approach 2:
The forensics software agent performs self-service by automatically deploying to the originating machine when suspect activity is detected, collecting necessary data, and then self-removing after completion. This automated self-service approach eliminates the need for constant human intervention and reduces the ongoing resource burden of manual monitoring and analysis.
3Device complexity
If generic security monitoring is used, then system simplicity is maintained, but specialized response to specific threats is lost
Solution Approach 1:
The forensics software agent is designed with multi-functionality to handle various types of suspect network communications and threats. It can adapt its data collection and analysis based on the specific threat detected, providing specialized responses while being deployed from a universal platform. This allows the system to maintain relative simplicity in deployment while achieving high adaptability in response to different threats.
Solution Approach 2:
The system transitions from a static, generic monitoring approach to a dynamic response mechanism. When suspect activity is detected, the forensics software agent dynamically adapts its behavior based on the specific threat type, collecting relevant data and applying appropriate response actions. This dynamic capability enables specialized responses to specific threats while maintaining system simplicity through automated decision-making.
4Use of energy by moving object
If critical information is not collected, then resource consumption is reduced, but effective defense against attacks fails
Solution Approach 1:
The forensics software agent applies local quality by collecting specific types of data relevant to the detected threat rather than uniformly collecting all possible information. It tailors its data collection to the local context of the suspect activity, gathering only the critical information needed for effective defense while minimizing unnecessary resource consumption from collecting irrelevant data.
Data Source
AI summary
Methods and systems for detecting and preventing malicious software activity are presented. In one embodiment, a method is presented that includes monitoring network communications on a network. The method may also include detect a suspect network communication associated with a suspect network activity and, in response, determine an originating machine based on the suspect network activity. The method may further suspend network communications for the originating machine. A forensics software agent may then be selected based on the suspect network activity. Then, the forensics software agent may be deployed on the originating machine. After deployment, the forensics software agent may fetch computer forensics data from the originating machine. Once the computer forensics data is fetched, a response action may be selected and executed based on said computer forensics data.


