Network Security System Identifying Rogue Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems are ineffective in identifying and addressing rogue applications in communications networks, which pose security threats and operational challenges due to their inability to pinpoint specific malicious apps causing suspicious behavior.
Innovation Solution
A network security system that utilizes a combination of Network Behavioural Analysis (NBA) and app inventory data to generate a data structure correlating behavioral signatures with installed apps, filtering common apps, and using machine learning to identify apps most likely responsible for suspicious behavior, thereby isolating rogue applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network operators monitor and analyze device behavior to detect suspicious activities, then network security is improved, but the ability to identify specific rogue applications is insufficient
Solution Approach 1:
The patent segments the identification process into multiple components: device-level behavior monitoring, application-level inventory collection, and correlation analysis. By dividing the monitoring task into device behavior analysis and app inventory matching, the system achieves both broad security coverage and precise rogue app identification.
Solution Approach 2:
The patent introduces an intermediary correlation mechanism that connects device behavior data with application inventory data. This intermediary layer analyzes the relationship between suspicious behaviors and installed applications, enabling precise identification of rogue apps without requiring direct access to application code or secrets.
2Reliability
If operators revoke applications suspected of rogue behavior, then network security is improved, but false revocation of legitimate applications may occur
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously monitors device behavior before, during, and after application revocation. By analyzing whether suspicious behaviors persist or cease after revocation, the system can verify the accuracy of its identification and adjust future revocation decisions, reducing false positives while maintaining security.
3Measurement precision
If operators manually review applications to determine which should be revoked, then decision accuracy may be improved, but the process becomes too slow to address rapidly spreading threats
Solution Approach 1:
The patent enables the system to automatically perform the review and identification process through machine learning algorithms that analyze device behavior patterns and match them with application inventories. The system serves itself by autonomously identifying rogue applications and recommending revocation actions without requiring manual operator intervention for each case, thus maintaining high decision accuracy while achieving rapid response times.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention provides a network security method and system for use in a communications network, said network comprising a plurality of devices adapted to communicate over the network, at least one device capable of downloading or uploading an application over the network, said system comprises means for data capture on the network by receiving data from a first data source and a second data source; means for analysing comprising means for correlating data arising from network behaviour of at least one device obtained from the first data source and data from a second data source and means for generating a data structure; and based on said analyses of the generated data structure, means for identifying applications on devices which are behaving suspiciously.