Outbreak Pathology Inference via Social Network Telemetry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems are inadequate in proactively detecting and mitigating malware outbreaks, as they often focus solely on intra-enterprise telemetry data, neglecting social connections that can serve as vectors for malware propagation, leading to delayed detection and increased risk of network compromise.

Innovation Solution

The system employs a combination of telemetry graphing within enterprise networks and social graphing of user connections to infer potential malware propagation paths, using Hidden Markov processes to simulate outbreaks and identify bridge points of high risk, thereby enhancing the prediction and mitigation of malware spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security systems focus solely on intra-enterprise telemetry data, then the system complexity is reduced and ease of operation is improved, but the detection precision and reliability of malware outbreak detection deteriorate

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges intra-enterprise telemetry data with social network data into a unified analysis framework. The system combines data from multiple sources (network telemetry, social connections, user interactions) to create a comprehensive view of potential malware propagation paths, thereby improving detection precision without managing entirely separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security system is enhanced to perform multiple functions: traditional network security monitoring plus social network analysis. The same platform processes both intra-enterprise telemetry and external social connection data, making the system multi-functional and improving detection capabilities without requiring completely separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security systems incorporate both network telemetry data and social network data, then the reliability of malware outbreak detection is improved, but the device complexity increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces intermediary components that bridge network telemetry and social network data. These intermediaries process and normalize data from different sources before analysis, managing the complexity of integrating multiple data types while maintaining reliable detection through comprehensive data fusion.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If security systems use traditional reactive approaches, then the ease of operation is maintained, but the loss of time in detecting outbreaks increases

Engineering Contradiction:
Improvedetection timeVSAvoidoperational simplicity
Core Design Contradiction:
Loss of timeVSEase of operation

Solution Approach 1:

The system performs preliminary analysis by continuously monitoring both network telemetry and social network data for indicators of potential malware outbreaks. By detecting early signs of propagation through social connections before full outbreaks occur, the system reduces detection time while maintaining automated operation that does not significantly increase operational complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3238122B1Outbreak pathology inference
Publication Date: 2020.01.29 MCAFEE LLC
  • EP3238122B1 patent drawingFigure 1
  • EP3238122B1 patent drawingFigure 1A
  • EP3238122B1 patent drawingFigure 2~3

AI summary

In an example, a system and method for outbreak pathology inference are described. In certain computational ecosystems, malware programs and other malicious objects may infect a machine, and then attempt to infect additional machines that are "networked" to the first machine. In some cases, the network may be a physical or logical network, such as an enterprise network. However, "social networking" may also connect one machine to another, because users may share files or data with one another over social networks. In that case, client devices may be equipped with a telemetry engine to gather and report data about the machine, while a system management server receives reported telemetry. The system management server may use both logical networks and social networks to infer potential outbreak paths and behaviors of malware.