Network Traffic Analysis for Malicious Target Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to systematically identify and alert users to potential infections and malicious behavior based on abnormal internet traffic patterns, as they often misclassify targets and do not account for unusual traffic volumes that exceed human capabilities, indicating potential robot or malicious activity.
Innovation Solution
A system that collects and analyzes traffic from Network Service Subscriber Clients, categorizes targets as Trusted or Anomalous based on behavior, and provides users with warnings and cleanup tools by maintaining a central database of suspicious targets, utilizing a central server to distribute updates and alerts across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If web filters categorize new targets without systematic analysis, then categorization speed is improved, but measurement precision of malicious behavior detection deteriorates
Solution Approach 1:
The system performs preliminary traffic collection and behavioral analysis on uncategorized targets before final categorization. Web filters gather traffic data from multiple sources and analyze client behavior patterns in advance, then use this pre-analyzed information to rapidly categorize new targets while maintaining detection accuracy.
Solution Approach 2:
The system implements feedback loops where categorization results and traffic analysis data are continuously fed back to improve future categorization decisions. The central server receives traffic data from multiple web filters, analyzes patterns, and refines categorization algorithms based on observed malicious behavior, thereby improving both speed and precision over time.
2Measurement precision
If the system monitors all internet traffic in detail, then detection precision of malicious activity is improved, but device complexity increases
Solution Approach 1:
The system divides the monitoring function into segments distributed across multiple web filters deployed at different network locations. Each web filter handles local traffic monitoring and collects data independently, then sends findings to a central server for aggregate analysis. This segmentation reduces the complexity burden on any single device while maintaining comprehensive detection precision.
Solution Approach 2:
A central server acts as an intermediary that receives traffic data from multiple web filters and performs the complex analysis function. Instead of requiring each web filter to independently perform sophisticated malicious activity detection, the intermediary central server aggregates data and applies advanced analysis algorithms, thereby reducing individual device complexity while maintaining high detection precision.
3Reliability
If the system collects and analyzes traffic from multiple clients, then reliability of malicious behavior identification is improved, but loss of time in processing increases
Solution Approach 1:
Web filters continuously collect and pre-process traffic data from multiple clients in the background, maintaining ready-to-analyze datasets. When malicious behavior detection is needed, the pre-collected data from multiple sources is already available, enabling rapid reliability-based identification without time-consuming data gathering delays.
Solution Approach 2:
The system maintains continuous traffic collection and analysis operations from multiple clients simultaneously. Rather than batch-processing data periodically, the web filters and central server continuously monitor and analyze traffic streams, ensuring that reliable malicious behavior identification can occur immediately when suspicious patterns emerge, minimizing processing time delays.
Data Source
AI summary
A system at a central server and at a plurality of web filters is installed to observe traffic and to protect users from attempting connection to suspicious, malicious, and/or infectious targets. Targets are defined as Uniform Resource Identifiers (URI) and Internet Protocol (IP) addresses. Traffic is collected, analyzed, and reported for further analysis. Behavior is analyzed for each client attempting a connection to an uncategorized target. IP addresses and URIs are evaluated toward placement in either a Trusted target store or an Anomalous target store. The accumulated content of Anomalous target store is provided back to the Network Service Subscriber Clients. Warnings and tools are presented when appropriate.


