Network Traffic Flow Analysis for Malware Detection on Embedded Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional anti-malware technologies are ineffective in protecting devices that lack malware detection capabilities, such as embedded systems and those running in sandboxed environments, due to restrictions on third-party applications and limited support for malware protection installations.

Innovation Solution

A method for detecting malware on computing devices without malware protection capabilities involves monitoring network traffic flows, generating signatures, and comparing them to a database of known malware signatures to predict the presence of malware, with alerts and potential network traffic blocking if malware is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional anti-malware applications are installed on computing devices, then malware detection capability is improved, but device compatibility and ease of operation deteriorate due to restrictions on third-party applications and sandboxed environments

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments malware detection into two parts: (1) device-level protection for devices that can run anti-malware apps, and (2) network-level traffic analysis for devices that cannot. This segmentation allows the patent to protect sandboxed and embedded devices through network monitoring without requiring installation on those devices, while still providing direct protection on capable devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network-level intermediary (the malware detection system analyzing traffic flows) that mediates protection for devices incapable of running anti-malware applications. This intermediary monitors and analyzes network traffic from sandboxed and embedded devices, detecting malware indicators without requiring direct installation or access to the device's internal environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If malware protection applications are installed on all devices, then security coverage is improved, but device complexity and installation requirements worsen

Engineering Contradiction:
Improvesecurity coverageVSAvoidinstallation requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal malware detection system that serves multiple device types through a single network-level solution. The system can protect conventional devices, sandboxed devices, and embedded systems uniformly by analyzing network traffic, eliminating the need for different protection mechanisms for different device categories.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system provides self-service protection for devices that cannot install anti-malware software. By monitoring network traffic flows and analyzing patterns, the system automatically detects malware indicators and can block malicious traffic without requiring the target device to perform any special functions or installations.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If network traffic monitoring is implemented for all devices, then malware detection accuracy is improved, but processing time and computational resources worsen

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial monitoring by focusing computational resources on devices identified as high-risk (sandboxed and embedded devices without malware protection). Rather than analyzing all device traffic equally, the system selectively intensifies monitoring on vulnerable devices while using lighter monitoring on protected devices, optimizing the balance between detection accuracy and processing time.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10893058B1Malware detection and alerting for network connected devices based on traffic flow analysis on local network
Publication Date: 2021.01.12 GEN DIGITAL INC
  • US10893058B1 patent drawing
  • US10893058B1 patent drawing
  • US10893058B1 patent drawing

AI summary

As described, embodiments presented herein provide techniques for detecting malware on computing devices connected to a local network segment by observing the traffic flows of such devices and generating signatures characterizing such traffic flows. Doing so allows instances of malware to be detected on a variety of devices which can be connected to a computing network, but which lack the capability of directly detecting and preventing malware applications from infecting such devices.