Security Appliance Proactive Threat Detection via Activity Records

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting malicious activity in computing environments are reactive, focusing on identifying and preventing attacks after they have occurred, rather than predicting potential threats in advance.

Innovation Solution

A security appliance that monitors and analyzes communication between computing devices, extracts selective information, and compares it for matches to generate activity records, enabling the detection of potential threats before they materialize.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based malware scanning is used to detect malicious activity, then detection accuracy is improved, but response time is worsened because corrective action can only be taken after an attack has occurred

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by monitoring network communications and building activity records before malicious attacks occur. The system continuously collects communication data, extracts selective information, and generates baseline activity records that represent normal communication patterns. When a potential threat is detected, the system can immediately compare it against pre-established activity records, enabling rapid response without waiting for signature-based detection after an attack has already occurred.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive communication monitoring is implemented to predict potential threats, then security reliability is improved, but system complexity is worsened

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the extraction principle by selectively extracting specific information from network communications rather than analyzing all communication data in detail. The system extracts selective information such as communication patterns, data volumes, and timing characteristics to build activity records. This selective extraction approach maintains high security reliability by focusing on the most relevant indicators while reducing system complexity by avoiding comprehensive analysis of all communication metadata.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies segmentation by dividing the security monitoring system into distinct functional modules: communication monitoring, selective information extraction, activity record generation, and threat detection. Each module handles a specific aspect of the security analysis, which simplifies the overall system architecture while maintaining comprehensive monitoring capabilities. The activity records themselves are segmented by communication pairs, making them easier to manage and query.

Inventive Principle:
Principle #1Segmentation

3Difficulty of detecting and measuring

If activity records are generated for all communication pairs to enable proactive threat detection, then detection capability is improved, but data processing load is worsened

Engineering Contradiction:
Improvedetection capabilityVSAvoiddata processing load
Core Design Contradiction:
Difficulty of detecting and measuringVSPower

Solution Approach 1:

The patent applies partial action by generating activity records selectively for communication pairs that exhibit suspicious or unusual patterns rather than creating detailed records for all communications. The system monitors all network traffic but focuses computational resources on analyzing and recording activity for communications that deviate from normal patterns or match known threat indicators. This approach maintains high detection capability for malicious activities while reducing the overall data processing load by not exhaustively analyzing every communication pair.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10218733B1System and method for detecting a malicious activity in a computing environment
Publication Date: 2019.02.26 ARISTA NETWORKS INC
  • US10218733B1 patent drawing
  • US10218733B1 patent drawing
  • US10218733B1 patent drawing

AI summary

System and method for evaluating communication between a plurality of computing devices is disclosed. A plurality of communication between a user computer and at least one a destination computer is monitored by a security appliance. Selective information from the plurality of communication is extracted by the security appliance. Extracted selective information between a pair of communication is compared for a match. An activity record is generated for the user computer and at least one destination computer, based on the match.