Premise Gateway Malware Detection via Intermediary Packet Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online security solutions, particularly for detecting computer malware, face challenges in identifying infected devices within a subscriber's premise network due to address translation services like NAPT, which obscure the source of packets, making it difficult for ISPs to determine which devices are infected.
Innovation Solution
Implementing a malware detection system within the premise network, such as a premise gateway or another device, that analyzes packets and identifies infected devices using malware signatures and heuristic algorithms, allowing for specific detection and notification of infected devices without requiring extensive modification of existing hardware or subscriber action.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If address translation services (NAPT) are implemented in the gateway to conserve IP addresses, then the number of IP addresses required is reduced, but the ability to identify infected devices is lost because packets appear to originate from the gateway rather than individual devices
Solution Approach 1:
The patent introduces a malware detection device as an intermediary component positioned between the gateway and the infected devices. This mediator captures and analyzes packets before they undergo address translation, allowing identification of the actual infected device while still permitting NAPT to function for IP address conservation. The intermediary device extracts identifying information from packets prior to gateway processing.
Solution Approach 2:
The patent implements preliminary packet capture and analysis before the packets reach the gateway's NAPT function. By performing malware detection and device identification in advance of address translation, the system preserves the ability to identify infected devices while maintaining IP address conservation benefits. The detection occurs at the point where packets still contain original device identifying information.
2Device complexity
If malware detection is performed at the ISP network level, then infrastructure modifications are minimized, but device-level identification capability is insufficient due to gateway address translation
Solution Approach 1:
The patent positions a malware detection device as an intermediary at the customer premises, between the gateway and infected devices. This intermediary captures packets locally before gateway NAPT processing, enabling precise device identification without requiring complex ISP infrastructure modifications. The solution places the detection capability where packet identifying information is still accessible.
Solution Approach 2:
The patent shifts the malware detection function from the ISP network dimension to the customer premises dimension. By moving the detection device to the customer premises equipment, the system accesses packet information in a different operational dimension where device identification is possible before NAPT obscures it, avoiding the need for complex ISP-side infrastructure changes.
3Adaptability or versatility
If existing gateways are modified to include malware detection capabilities, then detection functionality is integrated, but hardware and software complexity increases significantly
Solution Approach 1:
The patent segments the malware detection functionality from the gateway itself, placing it in a separate malware detection device. This segmentation allows the gateway to maintain its existing simpler architecture while the detection device provides enhanced malware identification capabilities. The separation prevents complexity from being added to the gateway while still achieving integrated functionality.
Solution Approach 2:
The patent designs the malware detection device to work with standard gateway interfaces and protocols, making it universally compatible with existing gateway hardware. The detection device can be added to various gateway configurations without requiring custom modifications to each gateway model, achieving versatility through a universal detection solution that interfaces with standard gateway functions.
Data Source
AI summary
Novel solutions for detecting and/or treating malware on a subscriber's premise network. Such solutions can include, but are not limited to, tools and techniques that can detect, and/or enable the detection of, malware infections on individual subscriber devices within the subscriber's network. In a particular embodiment, for example, a premise gateway, or other device on the subscriber's premise network, is configured to analyze packets traveling through the premise gateway and, based on that analysis, identify one or more subscriber devices that are infected with malware.


