SoC Malware Traffic Detection Across Encrypted Network Streams
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing intrusion detection systems struggle to effectively detect malware traffic, especially when it is encrypted, leading to potential security breaches and operational compromises.
Innovation Solution
A system-on-a-chip (SoC) equipped with multiple hardware engines, including a machine learning (ML), cryptographic (CPT), and deep packet inspection (DPI) engines, capable of detecting malware traffic in both encrypted and non-encrypted streams by employing a traffic scanner to classify and process packets using shared memory and packet descriptors, enabling inline connections between engines to reduce latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple separate devices are used to detect different types of malware traffic (encrypted and non-encrypted), then detection capability is improved, but device complexity and network latency increase
Solution Approach 1:
The patent combines multiple intrusion detection functions into a single SoC device that integrates a classification engine, cryptographic engine, and deep packet inspection engine. This unified architecture detects both encrypted and non-encrypted malware traffic through one system, reducing the number of separate devices needed while maintaining comprehensive detection capability.
Solution Approach 2:
The SoC device performs multiple functions within a single system: the classification engine identifies traffic types, the cryptographic engine decrypts encrypted traffic, and the deep packet inspection engine analyzes both encrypted and decrypted traffic for malware. This multi-functional approach eliminates the need for separate specialized devices.
2Reliability
If multiple separate devices are deployed for comprehensive malware detection, then detection coverage is improved, but network processing time and latency increase
Solution Approach 1:
By merging classification, decryption, and inspection functions into a single inline SoC device, the system processes traffic through one unified pipeline rather than multiple sequential devices. This reduces network hops and processing delays while maintaining comprehensive detection coverage for both encrypted and non-encrypted traffic.
3Ease of manufacture
If traditional intrusion detection systems are used, then implementation simplicity is maintained, but ability to detect encrypted malware traffic deteriorates
Solution Approach 1:
The classification engine performs preliminary classification of incoming traffic to identify encrypted streams before they reach the inspection engine. The cryptographic engine then proactively decrypts identified encrypted traffic, enabling the deep packet inspection engine to detect malware that would otherwise be hidden in encrypted streams.
Data Source
AI summary
A system-on-a-chip (SoC) and corresponding method implement an intrusion detection system. The SoC comprises a plurality of hardware engines. The SoC employs the plurality of hardware engines to implement the intrusion detection system. The intrusion detection system is capable of detecting malware traffic in (i) a non-encrypted traffic stream, (ii) an encrypted traffic stream that can be decrypted by the SoC, and (iii) an encrypted traffic stream that cannot be decrypted by the SoC. The intrusion detection system performs an action responsive to detecting the malware traffic. The action is performed toward preventing malicious activity otherwise caused by the malware traffic.


