Network Security System for Malware Detection and Device Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication networks face significant security challenges due to malware and social engineering tactics, with traditional anti-virus programs providing limited protection and lacking mechanisms to effectively communicate security threats to devices and trigger corrective actions.

Innovation Solution

A network-based system that monitors traffic for security attacks, determines the type and severity of threats, and sends tailored corrective actions to affected devices through a secure communication channel, utilizing Intrusion Detection and Prevention Systems, DNS analysis, and Deep Packet Inspection to identify and mitigate malware and social engineering attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus programs are used for protection, then users have basic malware detection capability, but the protection is limited and malware can hide or circumvent the software

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidmalware stealth capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network-based security system as an intermediary between the user's computing device and malware threats. This external security system monitors network traffic, analyzes suspicious patterns, and provides additional protection layers that bypass the limitations of local anti-virus software. The security system acts as a mediator that can detect and block malware communications without requiring the malware to be directly detected on the endpoint device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If Intrusion Detection Systems monitor network activities for malicious activities, then security threats can be detected, but there is no mechanism to communicate threats to devices and trigger corrective actions

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidautomated response capability
Core Design Contradiction:
Difficulty of detecting and measuringVSEase of operation

Solution Approach 1:

The patent implements a feedback loop where the security system continuously monitors network traffic, detects security events, and automatically responds by communicating with affected devices. When a security threat is detected, the system sends notifications to the computing device and can automatically trigger corrective actions such as blocking malicious connections or isolating infected devices. This closed-loop feedback mechanism eliminates the gap between detection and response that exists in traditional IDS systems.

Inventive Principle:
Principle #23Feedback

3Object-generated harmful factors

If security systems block traffic suspected to be malware infected, then malware propagation can be prevented, but there is no system that leverages network based security intelligence to trigger corrective action on the device

Engineering Contradiction:
Improvemalware propagationVSAvoidcorrective action responsiveness
Core Design Contradiction:
Object-generated harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent employs preliminary action by proactively analyzing network traffic patterns and security events before malware can fully propagate or cause significant harm. The system detects early signs of security threats, communicates with affected devices in advance, and implements preventive measures such as blocking suspicious connections or preparing corrective actions. This proactive approach allows the system to address security issues before they escalate, rather than merely reacting after malware has already spread.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9055090B2Network based device security and controls
Publication Date: 2015.06.09 CELLCO PARTNERSHIP INC
  • US9055090B2 patent drawing
  • US9055090B2 patent drawing
  • US9055090B2 patent drawing

AI summary

Protection against security attacks involves monitoring network traffic for a computing device security attack and determining whether there is a security event, using one or more network based security tools. Next, it is determined whether an event pattern involving two or more security events meets a predetermined criteria. Upon determining that there is a security attack, corrective action is tailored, based on the type of the computing device, the operating system of the computing device, the type of security attack, and/or the available protection tools. A course of action is performed depending on whether an account of the computing device includes a security protection service. If there is a security protection service, a message is sent over a secure link to the computing device. This message includes the corrective action to cure the computing device from the security attack.