Network Traffic Analysis for Malicious Target Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to systematically identify and alert users to potential infections and malicious behavior based on abnormal internet traffic patterns, as they often misclassify targets and do not account for unusual traffic volumes that exceed human capabilities, indicating potential robot or malicious activity.

Innovation Solution

A system that collects and analyzes traffic from Network Service Subscriber Clients, categorizes targets as Trusted or Anomalous based on behavior, and provides users with warnings and cleanup tools by maintaining a central database of suspicious targets, utilizing a central server to distribute updates and alerts across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If web filters categorize new targets without systematic analysis, then categorization speed is improved, but measurement precision of malicious behavior detection deteriorates

Engineering Contradiction:
Improvecategorization speedVSAvoidmalicious behavior detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary traffic collection and behavioral analysis on uncategorized targets before final categorization. Web filters gather traffic data from multiple sources and analyze client behavior patterns in advance, then use this pre-analyzed information to rapidly categorize new targets while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where categorization results and traffic analysis data are continuously fed back to improve future categorization decisions. The central server receives traffic data from multiple web filters, analyzes patterns, and refines categorization algorithms based on observed malicious behavior, thereby improving both speed and precision over time.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If the system monitors all internet traffic in detail, then detection precision of malicious activity is improved, but device complexity increases

Engineering Contradiction:
Improvemalicious activity detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system divides the monitoring function into segments distributed across multiple web filters deployed at different network locations. Each web filter handles local traffic monitoring and collects data independently, then sends findings to a central server for aggregate analysis. This segmentation reduces the complexity burden on any single device while maintaining comprehensive detection precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A central server acts as an intermediary that receives traffic data from multiple web filters and performs the complex analysis function. Instead of requiring each web filter to independently perform sophisticated malicious activity detection, the intermediary central server aggregates data and applies advanced analysis algorithms, thereby reducing individual device complexity while maintaining high detection precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system collects and analyzes traffic from multiple clients, then reliability of malicious behavior identification is improved, but loss of time in processing increases

Engineering Contradiction:
Improvemalicious behavior identification reliabilityVSAvoidtraffic processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Web filters continuously collect and pre-process traffic data from multiple clients in the background, maintaining ready-to-analyze datasets. When malicious behavior detection is needed, the pre-collected data from multiple sources is already available, enabling rapid reliability-based identification without time-consuming data gathering delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous traffic collection and analysis operations from multiple clients simultaneously. Rather than batch-processing data periodically, the web filters and central server continuously monitor and analyze traffic streams, ensuring that reliable malicious behavior identification can occur immediately when suspicious patterns emerge, minimizing processing time delays.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8726384B2Apparatus, and system for determining and cautioning users of internet connected clients of potentially malicious software and method for operating such
Publication Date: 2014.05.13 BARRACUDA NETWORKS INC
  • US8726384B2 patent drawing
  • US8726384B2 patent drawing
  • US8726384B2 patent drawing

AI summary

A system at a central server and at a plurality of web filters is installed to observe traffic and to protect users from attempting connection to suspicious, malicious, and/or infectious targets. Targets are defined as Uniform Resource Identifiers (URI) and Internet Protocol (IP) addresses. Traffic is collected, analyzed, and reported for further analysis. Behavior is analyzed for each client attempting a connection to an uncategorized target. IP addresses and URIs are evaluated toward placement in either a Trusted target store or an Anomalous target store. The accumulated content of Anomalous target store is provided back to the Network Service Subscriber Clients. Warnings and tools are presented when appropriate.