Network Traffic Selection for Shellcode Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern computer networks, such as virtualized data centers and Software-Defined Networks (SDNs), the high volume of traffic makes it unfeasible to inspect all or most of the traffic for malicious executable code, leading to inefficiencies in detection and inspection processes.

Innovation Solution

A method and system that selectively inspect only portions of network traffic suspected of carrying executable software code, using traffic selection modules coupled to network switches or SDN controllers, which prioritize and identify potentially malicious traffic based on predefined criteria and external indications, reducing the volume of inspected traffic and enhancing detection efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all network traffic is inspected for malicious executable code, then detection completeness is improved, but inspection efficiency deteriorates due to high traffic volume

Engineering Contradiction:
Improvedetection completenessVSAvoidinspection efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments network traffic into different categories based on executable code detection characteristics. Traffic is divided into suspected executable traffic (requiring full inspection) and non-executable traffic (can be filtered or inspected lightly), allowing the system to maintain detection completeness for malicious code while improving overall inspection efficiency by not treating all traffic equally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different inspection qualities to different traffic segments. Instead of uniform inspection, the system applies intensive inspection to traffic suspected of carrying executable code (high local quality) while using lighter or no inspection for other traffic types (low local quality), thereby optimizing the balance between detection reliability and inspection efficiency.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If traffic selection criteria are made more strict to reduce false positives, then detection precision is improved, but detection sensitivity deteriorates

Engineering Contradiction:
Improvedetection precisionVSAvoiddetection sensitivity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements dynamic traffic selection criteria that adapt based on detected characteristics. The system continuously monitors traffic patterns and adjusts selection thresholds dynamically, allowing the system to maintain high precision when confident about malicious indicators while lowering thresholds to capture potential threats, thus balancing precision and sensitivity through adaptive rather than static criteria.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms that monitor detection results and adjust selection criteria accordingly. When false positives are detected, the system refines its criteria to reduce them while maintaining sensitivity. This feedback loop allows the system to optimize the balance between precision and sensitivity over time based on actual performance data.

Inventive Principle:
Principle #23Feedback

3Reliability

If inspection resources are increased to handle more traffic, then detection coverage is improved, but system complexity and cost increase

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the most critical traffic segments for intensive inspection. By identifying and separating suspected executable traffic from the rest of the network traffic, the system can allocate inspection resources efficiently - concentrating full inspection capabilities on the extracted malicious-suspected traffic while using simpler or no inspection for benign traffic, thereby achieving good detection coverage without proportionally increasing system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial inspection action to most traffic (using lightweight filtering) and reserves intensive inspection action for only the necessary portion of traffic suspected of carrying executable code. This partial action approach allows the system to maintain adequate detection coverage for malicious content while avoiding the excessive complexity and cost of intensive inspection for all traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9491190B2Dynamic selection of network traffic for file extraction shellcode detection
Publication Date: 2016.11.08 AKAMAI TECHNOLOGIES INC
  • US9491190B2 patent drawing
  • US9491190B2 patent drawing
  • US9491190B2 patent drawing

AI summary

A method for network security includes, in a computer network that exchanges traffic among multiple network endpoints using one or more network switches, configuring at least one network switch to transfer at least some of the traffic for inspection. Only a portion of the traffic, which is suspected of carrying executable software code, is selected from the transferred traffic. The selected portion of the traffic is inspected, so as to verify whether any of the executable software code is malicious.