Network-Based Predictive Anti-Malware Profile Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing diversity of portable network-focused devices with different operating systems complicates network access control, making it difficult to secure wireless networks and manage devices, and existing anti-malware solutions require cumbersome software installations on user devices, leading to user dissatisfaction and management challenges.

Innovation Solution

A system that uses a processor to generate profile data for hostile sources based on previous threats, determines expected interaction characteristics, and controls access without the need for anti-malware software on endpoints, leveraging predictive modeling and machine learning to authenticate and authorize devices without the use of EAP supplicants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anti-malware software is deployed on endpoints, then security protection is improved, but device complexity and user burden increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsoftware installation burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the anti-malware protection function from the endpoint device and relocates it to the network infrastructure. Instead of installing software on each user device, the system deploys machine learning models and threat detection capabilities on network servers, which then analyze and block malicious traffic at the network level, eliminating the need for endpoint software installation while maintaining security protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a network-based intermediary system that acts as a mediator between external threats and endpoint devices. This intermediary analyzes network traffic, identifies malicious sources using profile data and machine learning, and blocks threats before they reach endpoints, providing security without requiring software on the endpoint itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If EAP supplicants are deployed for network access control, then authentication capability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication capabilityVSAvoiduser satisfaction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication and authorization functionality from endpoint devices and consolidates it into a centralized network-based system. The network infrastructure performs all EAP supplicant functions, profile matching, and access control decisions, eliminating the need for users to install or configure authentication software on their devices while maintaining secure network access control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal network-based authentication system that handles multiple device types and operating systems through a single centralized platform. The system uses profile data and machine learning to accommodate diverse devices without requiring device-specific software, providing multi-functional authentication capability that works across all endpoint types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If network access control accounts for diverse device types, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvedevice compatibilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service system where the network infrastructure automatically adapts to diverse device types through machine learning and profile matching. The system autonomously analyzes device characteristics, creates appropriate profiles, and configures access policies without requiring manual setup or complex configuration, enabling device compatibility while eliminating management complexity for administrators and users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses parameter changes in the form of dynamic profile data and machine learning model adjustments to adapt to different device types. The system modifies its behavior and access policies based on analyzed device parameters and characteristics, providing adaptability across diverse devices through automated parameter adjustment rather than complex configuration management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11722517B1Predictive modeling for anti-malware solutions
Publication Date: 2023.08.08 WELLS FARGO BANK NA
  • US11722517B1 patent drawing
  • US11722517B1 patent drawing
  • US11722517B1 patent drawing

AI summary

Provided is predictive modeling for anti-malware solutions. A profile for a device is determined based on at least one characteristic identified from a successful attempt by the device to access a network. An expected characteristic for a next access attempt by the device to access the network is determined based on the profile. The characteristic of the next access attempt is matched to the expected characteristic. In response to determining that at least one characteristic of the next access attempt matches the expected characteristic, the next access attempt by the device to the network is automatically granted.