Network Threat Notification for Previously Sent Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security software does not notify recipient computers of network-based threats transmitted via email or instant messages, leading to potential harm and disruption until the threats are detected and removed.
Innovation Solution
A method and apparatus that analyze network activity to identify and notify recipient computers of previously communicated threats, updating security software and initiating security scans to mitigate the threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security software halts or terminates network processes to mitigate a detected threat, then the infected computer is protected from further harm, but the user experiences disruption in productivity and cannot exchange data with other computers
Solution Approach 1:
The system segments the security response by separating the infected computer's local security actions (quarantine, process termination) from the notification function. The notification is segmented as a separate communication sent to the recipient's computer, allowing the sender's productivity to be restored while the recipient receives targeted security alerts without affecting their own system operations.
2Loss of information
If security software only notifies the infected computer user of a detected threat, then the local user is aware of the threat, but the recipient computer remains unaware and vulnerable to harm from the received threat
Solution Approach 1:
The system implements feedback by having the security software on the infected computer not only detect and respond to threats locally but also generate notifications that are sent to the recipient's computer. This creates a feedback loop where threat information flows from the source to the destination, enabling the recipient to take preventive or remedial actions. The notification serves as feedback about the threat's presence and characteristics.
3Productivity
If the recipient computer operates without notification of received threats, then system operations continue uninterrupted, but the threat may cause harm or lie dormant preparing for an attack
Solution Approach 1:
The notification system performs preliminary action by alerting the recipient computer to the presence of a threat before the threat can execute harmful actions or establish dormant positions. The notification is sent immediately upon detection at the source, enabling the recipient to initiate security scans, update defenses, or isolate affected systems before damage occurs, thus maintaining productivity while preventing harm.
Data Source
AI summary
A method and apparatus for notifying a recipient of a threat within previously communicated data is described. In one embodiment, network activity amongst at least two computer is analyzed to determine a threat communicated to a computer of the at least two computers. Furthermore, the computer is notified as to the previous communication of the threat.


