Network Security Monitoring via Memory Footprint Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer systems connected to networks face threats and attacks that compromise their integrity and operational performance, with existing security systems struggling to effectively detect and mitigate malware and malicious payloads without impacting system reliability.
Innovation Solution
A method employing a separate electronic computing device to monitor protected computers by obtaining and comparing memory footprints and signatures, initiating security alerts when discrepancies are found, thereby detecting and minimizing the impact of security issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security systems (firewalls, intrusion protection) are deployed to protect computer systems, then security detection capability is improved, but system operational performance and reliability deteriorate due to the burden imposed on monitored systems
Solution Approach 1:
The security monitoring function is segmented from the protected computer system and implemented on a separate electronic computing device. This allows security detection to occur independently without burdening the operational system, resolving the contradiction between security detection capability and system operational performance
Solution Approach 2:
A separate electronic computing device acts as an intermediary between the protected computer and the security analysis system. This intermediary captures memory footprints and transmits them for analysis, enabling security monitoring without directly impacting the operational performance of the protected system
2Reliability
If comprehensive security monitoring is implemented on the protected computer, then security threat detection is improved, but system resource consumption and operational efficiency worsen
Solution Approach 1:
The security monitoring workload is extracted from the protected computer and transferred to a separate electronic computing device. Only essential memory footprint data is captured and transmitted, minimizing resource consumption on the protected system while maintaining comprehensive security detection capability
Solution Approach 2:
Instead of running full security analysis on the protected system, a copy of the memory footprint state is captured and analyzed on a separate device. This copying approach enables thorough security monitoring without consuming resources on the original system
Data Source
AI summary
At an electronic computing device, a first memory footprint is obtained for a protected computer. The protected computer is monitored with the electronic computing device. At the electronic computing device, a second memory footprint is obtained for the protected computer. The first memory footprint is compared with the second memory footprint. When the first memory footprint does not match the second memory footprint, a security alert is initiated for the protected computer.


