Network Security System with On-Demand Forensics Agent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, such as firewalls and endpoint detection and response (EDR), are inefficient in identifying and responding to malicious activities on networks, as they require substantial resources for constant monitoring and data collection, and lack specialized responses to specific threats, often losing critical information and failing to effectively defend against attacks.

Innovation Solution

A method and system that monitors network communications, detects suspect activities, suspends communication, deploys a forensics software agent to collect and analyze data, and determines a response action based on the analysis, using a policy management unit to select and execute appropriate actions such as terminating processes or isolating files, thereby addressing the inefficiencies of existing systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall or EDR is used to monitor network communications, then network security is improved, but resource consumption increases substantially

Engineering Contradiction:
Improvenetwork securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system segments the security monitoring function into two parts: a lightweight firewall/EDR component that runs continuously with minimal resource usage, and a forensics software agent that is deployed only when suspect activity is detected. This segmentation allows the system to maintain security while reducing overall resource consumption by avoiding constant operation of heavy monitoring components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary monitoring with the lightweight firewall/EDR to detect suspect network communications before deploying the full forensics software agent. This preliminary action allows the system to identify potential threats and only then activate the more resource-intensive analysis tools, optimizing resource usage while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If constant monitoring and data collection is performed, then detection capability is improved, but resource consumption increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

Instead of constant monitoring, the system uses periodic action by having the lightweight firewall/EDR monitor network communications and only triggering the full forensics software agent when suspect activity is detected. This periodic activation of the heavy-duty detection tools maintains detection capability while significantly reducing resource consumption compared to continuous operation.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The forensics software agent performs self-service by automatically deploying to the originating machine when suspect activity is detected, collecting necessary data, and then self-removing after completion. This automated self-service approach eliminates the need for constant human intervention and reduces the ongoing resource burden of manual monitoring and analysis.

Inventive Principle:
Principle #25Self-service

3Device complexity

If generic security monitoring is used, then system simplicity is maintained, but specialized response to specific threats is lost

Engineering Contradiction:
Improvesystem simplicityVSAvoidspecialized response capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The forensics software agent is designed with multi-functionality to handle various types of suspect network communications and threats. It can adapt its data collection and analysis based on the specific threat detected, providing specialized responses while being deployed from a universal platform. This allows the system to maintain relative simplicity in deployment while achieving high adaptability in response to different threats.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system transitions from a static, generic monitoring approach to a dynamic response mechanism. When suspect activity is detected, the forensics software agent dynamically adapts its behavior based on the specific threat type, collecting relevant data and applying appropriate response actions. This dynamic capability enables specialized responses to specific threats while maintaining system simplicity through automated decision-making.

Inventive Principle:
Principle #15Dynamics

4Use of energy by moving object

If critical information is not collected, then resource consumption is reduced, but effective defense against attacks fails

Engineering Contradiction:
Improveresource consumptionVSAvoideffective defense capability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The forensics software agent applies local quality by collecting specific types of data relevant to the detected threat rather than uniformly collecting all possible information. It tailors its data collection to the local context of the suspect activity, gathering only the critical information needed for effective defense while minimizing unnecessary resource consumption from collecting irrelevant data.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11916945B2Method and apparatus for combining a firewall and a forensics agent to detect and prevent malicious software activity
Publication Date: 2024.02.27 CROWDSTRIKE
  • US11916945B2 patent drawing
  • US11916945B2 patent drawing
  • US11916945B2 patent drawing

AI summary

Methods and systems for detecting and preventing malicious software activity are presented. In one embodiment, a method is presented that includes monitoring network communications on a network. The method may also include detect a suspect network communication associated with a suspect network activity and, in response, determine an originating machine based on the suspect network activity. The method may further suspend network communications for the originating machine. A forensics software agent may then be selected based on the suspect network activity. Then, the forensics software agent may be deployed on the originating machine. After deployment, the forensics software agent may fetch computer forensics data from the originating machine. Once the computer forensics data is fetched, a response action may be selected and executed based on said computer forensics data.