Premise Gateway Malware Detection via Intermediary Packet Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online security solutions, particularly for detecting computer malware, face challenges in identifying infected devices within a subscriber's premise network due to address translation services like NAPT, which obscure the source of packets, making it difficult for ISPs to determine which devices are infected.

Innovation Solution

Implementing a malware detection system within the premise network, such as a premise gateway or another device, that analyzes packets and identifies infected devices using malware signatures and heuristic algorithms, allowing for specific detection and notification of infected devices without requiring extensive modification of existing hardware or subscriber action.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If address translation services (NAPT) are implemented in the gateway to conserve IP addresses, then the number of IP addresses required is reduced, but the ability to identify infected devices is lost because packets appear to originate from the gateway rather than individual devices

Engineering Contradiction:
Improvenumber of IP addressesVSAvoiddevice identification accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent introduces a malware detection device as an intermediary component positioned between the gateway and the infected devices. This mediator captures and analyzes packets before they undergo address translation, allowing identification of the actual infected device while still permitting NAPT to function for IP address conservation. The intermediary device extracts identifying information from packets prior to gateway processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary packet capture and analysis before the packets reach the gateway's NAPT function. By performing malware detection and device identification in advance of address translation, the system preserves the ability to identify infected devices while maintaining IP address conservation benefits. The detection occurs at the point where packets still contain original device identifying information.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If malware detection is performed at the ISP network level, then infrastructure modifications are minimized, but device-level identification capability is insufficient due to gateway address translation

Engineering Contradiction:
Improveinfrastructure modification complexityVSAvoidinfected device identification
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent positions a malware detection device as an intermediary at the customer premises, between the gateway and infected devices. This intermediary captures packets locally before gateway NAPT processing, enabling precise device identification without requiring complex ISP infrastructure modifications. The solution places the detection capability where packet identifying information is still accessible.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent shifts the malware detection function from the ISP network dimension to the customer premises dimension. By moving the detection device to the customer premises equipment, the system accesses packet information in a different operational dimension where device identification is possible before NAPT obscures it, avoiding the need for complex ISP-side infrastructure changes.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If existing gateways are modified to include malware detection capabilities, then detection functionality is integrated, but hardware and software complexity increases significantly

Engineering Contradiction:
Improvegateway functionalityVSAvoidgateway hardware and software
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the malware detection functionality from the gateway itself, placing it in a separate malware detection device. This segmentation allows the gateway to maintain its existing simpler architecture while the detection device provides enhanced malware identification capabilities. The separation prevents complexity from being added to the gateway while still achieving integrated functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs the malware detection device to work with standard gateway interfaces and protocols, making it universally compatible with existing gateway hardware. The detection device can be added to various gateway configurations without requiring custom modifications to each gateway model, achieving versatility through a universal detection solution that interfaces with standard gateway functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10484412B2Identification of infected devices in broadband environments
Publication Date: 2019.11.19 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US10484412B2 patent drawing
  • US10484412B2 patent drawing
  • US10484412B2 patent drawing

AI summary

Novel solutions for detecting and/or treating malware on a subscriber's premise network. Such solutions can include, but are not limited to, tools and techniques that can detect, and/or enable the detection of, malware infections on individual subscriber devices within the subscriber's network. In a particular embodiment, for example, a premise gateway, or other device on the subscriber's premise network, is configured to analyze packets traveling through the premise gateway and, based on that analysis, identify one or more subscriber devices that are infected with malware.