Risk-Based Data Routing and Sampling for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity and throughput of network computing and storage resources make it difficult to effectively detect and mitigate malicious data without affecting legitimate data, as existing detection and mitigation regimes often overzealously impact customer experiences.
Innovation Solution
Implementing a risk analyzer that uses risk classifiers to determine risk levels and profiles for transiting data, routing malicious data to quarantined hosts with additional mitigation measures while allowing legitimate data to be routed normally, and using a sandbox to analyze sampled data for improved risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If overzealous detection and mitigation regimes are implemented to handle malicious data, then security is improved, but customer experience deteriorates due to disruption of legitimate data
Solution Approach 1:
The patent applies partial action by implementing data sampling where only a subset of transiting data is analyzed by the sandbox rather than all data. This reduces the burden on detection systems while still maintaining security effectiveness. The risk classifier processes data at a higher level to identify suspicious patterns without requiring exhaustive analysis of every data packet, thus balancing security with customer experience.
Solution Approach 2:
The detection system is segmented into multiple components: a risk classifier that performs initial assessment, a sandbox that performs detailed analysis on sampled data, and a routing mechanism that directs data based on risk levels. This segmentation allows different parts of the system to operate at different levels of scrutiny, reducing overall disruption while maintaining security.
2Measurement precision
If comprehensive detection regimes are implemented to identify malicious data, then detection accuracy is improved, but system complexity increases making implementation difficult
Solution Approach 1:
The detection system is divided into modular components: a risk classifier that performs initial filtering and a sandbox that performs detailed analysis only on suspicious samples. This segmentation reduces overall system complexity by avoiding the need for comprehensive complex analysis on all data while maintaining high detection accuracy through focused scrutiny of suspicious cases.
Solution Approach 2:
The system uses partial action by analyzing only a sample of transiting data through the sandbox rather than performing comprehensive analysis on all data. This approach maintains high detection accuracy for malicious data while significantly reducing the computational complexity and resource requirements of the overall system.
3Reliability
If all transiting data is analyzed to ensure security, then security coverage is improved, but processing time increases affecting data throughput
Solution Approach 1:
The system implements partial analysis by using the risk classifier to quickly assess all data and then subjecting only suspicious samples to detailed sandbox analysis. This maintains comprehensive security coverage for identifying malicious data while minimizing processing time by avoiding exhaustive analysis of legitimate data.
Solution Approach 2:
The analysis process is segmented into two stages: rapid initial classification of all data by the risk classifier, followed by detailed analysis only of suspicious samples by the sandbox. This segmentation enables the system to maintain high security coverage while processing data at near-line speed for the majority of legitimate traffic.
Data Source
AI summary
Techniques described and suggested herein include various systems and methods for determining risk levels associated with transiting data, and routing portions of the data in accordance with the determined risk levels. For example, a risk analyzer may apply risk classifiers to transiting data to determine overall risk levels of some or all of the transiting data. A traffic router may route transiting data according to determined risk profiles for the data. A sandbox may be implemented to compare, for a given input, expected and observed outputs for a subset of transiting data, so as to determine risk profiles associated with at least the subset.


