Network Traffic Analysis for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring techniques are insufficient in detecting security risks, data transmission issues, and configuration problems, particularly in larger networks, as they often rely on local monitoring and may fail to identify compromised systems or hidden malicious activities within the network.

Innovation Solution

The proposed solution involves collecting and correlating network data from both endpoint nodes and switches to identify discrepancies, using passive scanning to build a comprehensive picture of network traffic, and analyzing packet information to detect unauthorized activities or hardware failures, thereby enhancing security threat detection and network health assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If local monitoring techniques are used to detect network security risks, then the monitoring system is simple to implement, but the detection accuracy is insufficient and cannot identify hidden malicious activities

Engineering Contradiction:
Improvedetection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into multiple independent components: endpoint agents installed on individual devices, network switches with embedded monitoring capabilities, and a central server for data correlation. Each component performs localized monitoring functions, and their combined data provides comprehensive detection accuracy without requiring a single complex centralized monitoring system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested monitoring layers where endpoint agents operate within individual devices, network switches monitor traffic between devices, and the central server correlates data from all sources. This nested architecture enables deep detection of hidden malicious activities by combining insights from multiple monitoring levels, effectively solving the contradiction between detection accuracy and system complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Measurement precision

If comprehensive network data collection from all endpoints and switches is implemented, then security threat detection accuracy improves, but the quantity of data to be processed increases significantly

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the essential and relevant features from the comprehensive network data collected from endpoints and switches. Instead of processing all raw data, the patent identifies and extracts key indicators such as traffic patterns, anomaly scores, and security-relevant metadata, significantly reducing the data volume while maintaining high detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements selective data collection where endpoints and switches transmit only the most critical information to the central server. By performing partial monitoring actions at the source and transmitting only essential data, the system achieves comprehensive security detection without the burden of processing excessive data volumes.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If passive scanning is used to build a comprehensive picture of network traffic, then unauthorized activities can be detected without disrupting network operations, but the time required to analyze and correlate data increases

Engineering Contradiction:
Improvenetwork operation continuityVSAvoiddata analysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary data processing and filtering at the endpoint agents and network switches before data reaches the central server. By performing initial analysis and pre-processing actions locally, the system reduces the time required for comprehensive data correlation at the central server, thus maintaining network operation continuity while accelerating overall analysis time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms where the central server sends configuration updates and analysis rules back to endpoint agents and switches in real-time. This feedback loop enables continuous optimization of data collection and analysis processes, reducing analysis time while maintaining reliable passive scanning that does not disrupt network operations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10440049B2Network traffic analysis for malware detection and performance reporting
Publication Date: 2019.10.08 PAYPAL INC
  • US10440049B2 patent drawing
  • US10440049B2 patent drawing
  • US10440049B2 patent drawing

AI summary

Computer networks, particularly larger networks, may have various issues and vulnerabilities. By collecting network traffic data from a network in multiple different locations, then analyzing correlations in this data, performance issues and security risks can be uncovered. Techniques disclosed herein can help mitigate risks posed by malware, mitigate network performance issues, and also help provide a detailed network map of devices, services, and/or operating systems that are present on a network.