Network Traffic Selection for Shellcode Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In modern computer networks, such as virtualized data centers and Software-Defined Networks (SDNs), the high volume of traffic makes it unfeasible to inspect all or most of the traffic for malicious executable code, leading to inefficiencies in detection and inspection processes.
Innovation Solution
A method and system that selectively inspect only portions of network traffic suspected of carrying executable software code, using traffic selection modules coupled to network switches or SDN controllers, which prioritize and identify potentially malicious traffic based on predefined criteria and external indications, reducing the volume of inspected traffic and enhancing detection efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all network traffic is inspected for malicious executable code, then detection completeness is improved, but inspection efficiency deteriorates due to high traffic volume
Solution Approach 1:
The patent segments network traffic into different categories based on executable code detection characteristics. Traffic is divided into suspected executable traffic (requiring full inspection) and non-executable traffic (can be filtered or inspected lightly), allowing the system to maintain detection completeness for malicious code while improving overall inspection efficiency by not treating all traffic equally.
Solution Approach 2:
The patent applies different inspection qualities to different traffic segments. Instead of uniform inspection, the system applies intensive inspection to traffic suspected of carrying executable code (high local quality) while using lighter or no inspection for other traffic types (low local quality), thereby optimizing the balance between detection reliability and inspection efficiency.
2Measurement precision
If traffic selection criteria are made more strict to reduce false positives, then detection precision is improved, but detection sensitivity deteriorates
Solution Approach 1:
The patent implements dynamic traffic selection criteria that adapt based on detected characteristics. The system continuously monitors traffic patterns and adjusts selection thresholds dynamically, allowing the system to maintain high precision when confident about malicious indicators while lowering thresholds to capture potential threats, thus balancing precision and sensitivity through adaptive rather than static criteria.
Solution Approach 2:
The system incorporates feedback mechanisms that monitor detection results and adjust selection criteria accordingly. When false positives are detected, the system refines its criteria to reduce them while maintaining sensitivity. This feedback loop allows the system to optimize the balance between precision and sensitivity over time based on actual performance data.
3Reliability
If inspection resources are increased to handle more traffic, then detection coverage is improved, but system complexity and cost increase
Solution Approach 1:
The patent extracts only the most critical traffic segments for intensive inspection. By identifying and separating suspected executable traffic from the rest of the network traffic, the system can allocate inspection resources efficiently - concentrating full inspection capabilities on the extracted malicious-suspected traffic while using simpler or no inspection for benign traffic, thereby achieving good detection coverage without proportionally increasing system complexity.
Solution Approach 2:
The system applies partial inspection action to most traffic (using lightweight filtering) and reserves intensive inspection action for only the necessary portion of traffic suspected of carrying executable code. This partial action approach allows the system to maintain adequate detection coverage for malicious content while avoiding the excessive complexity and cost of intensive inspection for all traffic.
Data Source
AI summary
A method for network security includes, in a computer network that exchanges traffic among multiple network endpoints using one or more network switches, configuring at least one network switch to transfer at least some of the traffic for inspection. Only a portion of the traffic, which is suspected of carrying executable software code, is selected from the transferred traffic. The selected portion of the traffic is inspected, so as to verify whether any of the executable software code is malicious.


