Network Threat Notification for Previously Sent Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security software does not notify recipient computers of network-based threats transmitted via email or instant messages, leading to potential harm and disruption until the threats are detected and removed.

Innovation Solution

A method and apparatus that analyze network activity to identify and notify recipient computers of previously communicated threats, updating security software and initiating security scans to mitigate the threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security software halts or terminates network processes to mitigate a detected threat, then the infected computer is protected from further harm, but the user experiences disruption in productivity and cannot exchange data with other computers

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata exchange capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the security response by separating the infected computer's local security actions (quarantine, process termination) from the notification function. The notification is segmented as a separate communication sent to the recipient's computer, allowing the sender's productivity to be restored while the recipient receives targeted security alerts without affecting their own system operations.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If security software only notifies the infected computer user of a detected threat, then the local user is aware of the threat, but the recipient computer remains unaware and vulnerable to harm from the received threat

Engineering Contradiction:
Improvethreat awarenessVSAvoidrecipient computer vulnerability
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback by having the security software on the infected computer not only detect and respond to threats locally but also generate notifications that are sent to the recipient's computer. This creates a feedback loop where threat information flows from the source to the destination, enabling the recipient to take preventive or remedial actions. The notification serves as feedback about the threat's presence and characteristics.

Inventive Principle:
Principle #23Feedback

3Productivity

If the recipient computer operates without notification of received threats, then system operations continue uninterrupted, but the threat may cause harm or lie dormant preparing for an attack

Engineering Contradiction:
Improvesystem operation continuityVSAvoidcomputer security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The notification system performs preliminary action by alerting the recipient computer to the presence of a threat before the threat can execute harmful actions or establish dormant positions. The notification is sent immediately upon detection at the source, enabling the recipient to initiate security scans, update defenses, or isolate affected systems before damage occurs, thus maintaining productivity while preventing harm.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8819823B1Method and apparatus for notifying a recipient of a threat within previously communicated data
Publication Date: 2014.08.26 CA TECH INC
  • US8819823B1 patent drawing
  • US8819823B1 patent drawing
  • US8819823B1 patent drawing

AI summary

A method and apparatus for notifying a recipient of a threat within previously communicated data is described. In one embodiment, network activity amongst at least two computer is analyzed to determine a threat communicated to a computer of the at least two computers. Furthermore, the computer is notified as to the previous communication of the threat.