Self-Healing Security System for Network Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems for computer systems and networks rely on periodic updates of virus definitions, which makes them ineffective against newly created malicious programs and allows quick spread of attacks across networks due to infrequent updates.

Innovation Solution

A self-healing security system with security agents that monitor processing operations within host computer systems, detect security violations, and prevent similar sequences of operations that led to violations, learning from past attacks to prevent future occurrences without relying on external updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virus detection software periodically downloads virus definitions from remote servers, then the security software can identify known viruses, but it becomes ineffective against newly created malicious programs that have not yet been added to the virus definition database

Engineering Contradiction:
Improveability to detect known virusesVSAvoidability to detect new malicious programs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system performs preliminary monitoring and recording of processing operations before malicious programs can execute or spread. By capturing sequences of operations in advance and storing them for later analysis, the system prepares detection patterns proactively rather than reactively, enabling identification of new threats before they become widespread

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where processing operations are monitored, analyzed for security violations, and used to update detection rules. The analysis component examines recorded operation sequences and provides feedback to refine security policies, creating a self-improving system that adapts to new threats without requiring external virus definition updates

Inventive Principle:
Principle #23Feedback

2Stability of the object's composition

If virus detection software relies on periodic updates from centralized servers, then it maintains a curated database of known threats, but it allows quick spread of attacks across networks due to infrequent updates

Engineering Contradiction:
Improveintegrity of virus definition databaseVSAvoidresponse time to new threats
Core Design Contradiction:
Stability of the object's compositionVSSpeed

Solution Approach 1:

The security system performs self-service by autonomously monitoring its own processing operations and automatically analyzing security violations without requiring external intervention. Each system monitors itself and contributes findings to the collective knowledge base, enabling rapid local adaptation and eliminating dependency on centralized update cycles

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent combines multiple monitoring functions into a unified security framework that integrates operation recording, violation detection, and analysis into a single coordinated system. This merging enables seamless real-time response across the network by combining data from multiple sources into comprehensive security intelligence

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If security systems monitor and record all processing operations to detect security violations, then they can identify malicious attacks, but the complexity of monitoring and analyzing all operations increases significantly

Engineering Contradiction:
Improvedetection accuracy of security violationsVSAvoidcomplexity of monitoring and analysis system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential and relevant processing operations for security monitoring, separating critical security-related operations from routine benign operations. By focusing monitoring resources on high-risk operations and using heuristic analysis to identify suspicious patterns, the system reduces analysis complexity while maintaining detection accuracy

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7979889B2Methods and apparatus providing security to computer systems and networks
Publication Date: 2011.07.12 CISCO TECHNOLOGY INC
  • US7979889B2 patent drawing
  • US7979889B2 patent drawing
  • US7979889B2 patent drawing

AI summary

A system provides security to a computerized device by detecting a sequence of related processing operations within the computerized device and recording the sequence of related processing operations in a security history. The system identifies a security violation when a processing operation performed in the computerized device produces an undesired processing outcome that violates a security policy and subsequently detecting attempted performance of at least one processing operation that attempts to produce the undesired processing outcome that violates the security policy and in response, denies operation of the processing operation(s) within the computerized device to avoid violation of the security policy.