Security Device Automates Suspect Object Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems require significant resources to detect and test suspect objects on client devices for malicious activity, which can be time-consuming and costly, and may not efficiently prevent the spread of malicious files within a customer network.

Innovation Solution

A security device detects suspicious activity on client devices, automatically obtains and tests suspect objects using a remote management interface, filters known non-malicious objects, and determines whether the suspect objects are malicious, thereby reducing administrative resources and improving network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security systems manually detect and test suspect objects on client devices, then detection accuracy can be maintained, but significant administrative resources and time are required

Engineering Contradiction:
Improvedetection accuracyVSAvoidadministrative resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables client devices to automatically detect and report their own suspect objects to the security server. The client device performs self-diagnosis by monitoring its own operations and automatically transmitting suspicious objects for analysis, eliminating the need for manual administrative intervention while maintaining detection accuracy through automated resource acquisition and analysis processes.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If security systems manually obtain and test suspect objects, then thorough analysis can be performed, but the process becomes time-consuming and delays threat response

Engineering Contradiction:
Improveanalysis thoroughnessVSAvoidthreat response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically acquiring suspect objects from client devices and initiating analysis processes immediately upon detection of suspicious activity. The security server proactively retrieves objects before they can spread further, and parallel analysis processes are launched simultaneously, ensuring both thorough examination and rapid response without sequential delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system accelerates the security analysis process by implementing automated parallel processing of multiple suspect objects simultaneously. Multiple analysis operations run concurrently on the security server, allowing rapid throughput of numerous objects without the time-consuming sequential handling that would otherwise be required, thus rushing through the analysis phase while maintaining thoroughness.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Reliability

If comprehensive testing of all suspect objects is performed, then all malicious threats can be identified, but the resource cost and complexity increase significantly

Engineering Contradiction:
Improvethreat identification completenessVSAvoidsystem resource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential suspect objects that are most likely to be malicious, rather than analyzing every single file on client devices. The automated resource acquisition process selectively retrieves objects based on suspicion criteria, and the analysis phase focuses computational resources on these extracted candidates, maintaining complete threat identification while reducing overall system complexity and resource requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If manual security monitoring is implemented, then control over security operations can be maintained, but the ease of operation and automation level decrease

Engineering Contradiction:
Improveautomation levelVSAvoidmanual control capability
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The system implements automated feedback loops where the security server receives analysis results from suspect objects and automatically transmits remediation instructions back to client devices. This closed-loop feedback mechanism maintains high automation levels by eliminating manual intervention in the control cycle, while administrators retain oversight through the ability to monitor and configure the automated processes, thus achieving ease of operation without complete loss of manual control capability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9654496B1Obtaining suspect objects based on detecting suspicious activity
Publication Date: 2017.05.16 JUNIPER NETWORKS INC
  • US9654496B1 patent drawing
  • US9654496B1 patent drawing
  • US9654496B1 patent drawing

AI summary

A device may detect a suspicious activity. The device may automatically obtain a suspect object from a client device that is associated with the suspicious activity and based on detecting the suspicious activity. The suspect object may be an object that is possibly associated with the suspicious activity. The device may determine that the suspect object is malicious. The device may perform an action based on determining that the suspect object is malicious.