Network Traffic Analysis for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring techniques are insufficient in detecting security risks, data transmission issues, and configuration problems, particularly in larger networks, as they often rely on local monitoring and may fail to identify compromised systems or hidden malicious activities within the network.
Innovation Solution
The proposed solution involves collecting and correlating network data from both endpoint nodes and switches to identify discrepancies, using passive scanning to build a comprehensive picture of network traffic, and analyzing packet information to detect unauthorized activities or hardware failures, thereby enhancing security threat detection and network health assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If local monitoring techniques are used to detect network security risks, then the monitoring system is simple to implement, but the detection accuracy is insufficient and cannot identify hidden malicious activities
Solution Approach 1:
The monitoring system is segmented into multiple independent components: endpoint agents installed on individual devices, network switches with embedded monitoring capabilities, and a central server for data correlation. Each component performs localized monitoring functions, and their combined data provides comprehensive detection accuracy without requiring a single complex centralized monitoring system.
Solution Approach 2:
The patent implements nested monitoring layers where endpoint agents operate within individual devices, network switches monitor traffic between devices, and the central server correlates data from all sources. This nested architecture enables deep detection of hidden malicious activities by combining insights from multiple monitoring levels, effectively solving the contradiction between detection accuracy and system complexity.
2Measurement precision
If comprehensive network data collection from all endpoints and switches is implemented, then security threat detection accuracy improves, but the quantity of data to be processed increases significantly
Solution Approach 1:
The system extracts only the essential and relevant features from the comprehensive network data collected from endpoints and switches. Instead of processing all raw data, the patent identifies and extracts key indicators such as traffic patterns, anomaly scores, and security-relevant metadata, significantly reducing the data volume while maintaining high detection accuracy.
Solution Approach 2:
The patent implements selective data collection where endpoints and switches transmit only the most critical information to the central server. By performing partial monitoring actions at the source and transmitting only essential data, the system achieves comprehensive security detection without the burden of processing excessive data volumes.
3Reliability
If passive scanning is used to build a comprehensive picture of network traffic, then unauthorized activities can be detected without disrupting network operations, but the time required to analyze and correlate data increases
Solution Approach 1:
The patent implements preliminary data processing and filtering at the endpoint agents and network switches before data reaches the central server. By performing initial analysis and pre-processing actions locally, the system reduces the time required for comprehensive data correlation at the central server, thus maintaining network operation continuity while accelerating overall analysis time.
Solution Approach 2:
The system incorporates feedback mechanisms where the central server sends configuration updates and analysis rules back to endpoint agents and switches in real-time. This feedback loop enables continuous optimization of data collection and analysis processes, reducing analysis time while maintaining reliable passive scanning that does not disrupt network operations.
Data Source
AI summary
Computer networks, particularly larger networks, may have various issues and vulnerabilities. By collecting network traffic data from a network in multiple different locations, then analyzing correlations in this data, performance issues and security risks can be uncovered. Techniques disclosed herein can help mitigate risks posed by malware, mitigate network performance issues, and also help provide a detailed network map of devices, services, and/or operating systems that are present on a network.


