Network Traffic Flow Analysis for Malware Detection on Embedded Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional anti-malware technologies are ineffective in protecting devices that lack malware detection capabilities, such as embedded systems and those running in sandboxed environments, due to restrictions on third-party applications and limited support for malware protection installations.
Innovation Solution
A method for detecting malware on computing devices without malware protection capabilities involves monitoring network traffic flows, generating signatures, and comparing them to a database of known malware signatures to predict the presence of malware, with alerts and potential network traffic blocking if malware is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional anti-malware applications are installed on computing devices, then malware detection capability is improved, but device compatibility and ease of operation deteriorate due to restrictions on third-party applications and sandboxed environments
Solution Approach 1:
The system segments malware detection into two parts: (1) device-level protection for devices that can run anti-malware apps, and (2) network-level traffic analysis for devices that cannot. This segmentation allows the patent to protect sandboxed and embedded devices through network monitoring without requiring installation on those devices, while still providing direct protection on capable devices.
Solution Approach 2:
The patent introduces a network-level intermediary (the malware detection system analyzing traffic flows) that mediates protection for devices incapable of running anti-malware applications. This intermediary monitors and analyzes network traffic from sandboxed and embedded devices, detecting malware indicators without requiring direct installation or access to the device's internal environment.
2Reliability
If malware protection applications are installed on all devices, then security coverage is improved, but device complexity and installation requirements worsen
Solution Approach 1:
The patent creates a universal malware detection system that serves multiple device types through a single network-level solution. The system can protect conventional devices, sandboxed devices, and embedded systems uniformly by analyzing network traffic, eliminating the need for different protection mechanisms for different device categories.
Solution Approach 2:
The system provides self-service protection for devices that cannot install anti-malware software. By monitoring network traffic flows and analyzing patterns, the system automatically detects malware indicators and can block malicious traffic without requiring the target device to perform any special functions or installations.
3Measurement precision
If network traffic monitoring is implemented for all devices, then malware detection accuracy is improved, but processing time and computational resources worsen
Solution Approach 1:
The system applies partial monitoring by focusing computational resources on devices identified as high-risk (sandboxed and embedded devices without malware protection). Rather than analyzing all device traffic equally, the system selectively intensifies monitoring on vulnerable devices while using lighter monitoring on protected devices, optimizing the balance between detection accuracy and processing time.
Data Source
AI summary
As described, embodiments presented herein provide techniques for detecting malware on computing devices connected to a local network segment by observing the traffic flows of such devices and generating signatures characterizing such traffic flows. Doing so allows instances of malware to be detected on a variety of devices which can be connected to a computing network, but which lack the capability of directly detecting and preventing malware applications from infecting such devices.


