SoC Malware Traffic Detection Across Encrypted Network Streams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems struggle to effectively detect malware traffic, especially when it is encrypted, leading to potential security breaches and operational compromises.

Innovation Solution

A system-on-a-chip (SoC) equipped with multiple hardware engines, including a machine learning (ML), cryptographic (CPT), and deep packet inspection (DPI) engines, capable of detecting malware traffic in both encrypted and non-encrypted streams by employing a traffic scanner to classify and process packets using shared memory and packet descriptors, enabling inline connections between engines to reduce latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate devices are used to detect different types of malware traffic (encrypted and non-encrypted), then detection capability is improved, but device complexity and network latency increase

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple intrusion detection functions into a single SoC device that integrates a classification engine, cryptographic engine, and deep packet inspection engine. This unified architecture detects both encrypted and non-encrypted malware traffic through one system, reducing the number of separate devices needed while maintaining comprehensive detection capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The SoC device performs multiple functions within a single system: the classification engine identifies traffic types, the cryptographic engine decrypts encrypted traffic, and the deep packet inspection engine analyzes both encrypted and decrypted traffic for malware. This multi-functional approach eliminates the need for separate specialized devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate devices are deployed for comprehensive malware detection, then detection coverage is improved, but network processing time and latency increase

Engineering Contradiction:
Improvemalware detection coverageVSAvoidnetwork processing latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By merging classification, decryption, and inspection functions into a single inline SoC device, the system processes traffic through one unified pipeline rather than multiple sequential devices. This reduces network hops and processing delays while maintaining comprehensive detection coverage for both encrypted and non-encrypted traffic.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of manufacture

If traditional intrusion detection systems are used, then implementation simplicity is maintained, but ability to detect encrypted malware traffic deteriorates

Engineering Contradiction:
Improvesystem implementation simplicityVSAvoidencrypted traffic detection
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The classification engine performs preliminary classification of incoming traffic to identify encrypted streams before they reach the inspection engine. The cryptographic engine then proactively decrypts identified encrypted traffic, enabling the deep packet inspection engine to detect malware that would otherwise be hidden in encrypted streams.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12549565B2System and method for intrusion detection of malware traffic
Publication Date: 2026.02.10 MARVELL ASIA PTE LTD
  • US12549565B2 patent drawing
  • US12549565B2 patent drawing
  • US12549565B2 patent drawing

AI summary

A system-on-a-chip (SoC) and corresponding method implement an intrusion detection system. The SoC comprises a plurality of hardware engines. The SoC employs the plurality of hardware engines to implement the intrusion detection system. The intrusion detection system is capable of detecting malware traffic in (i) a non-encrypted traffic stream, (ii) an encrypted traffic stream that can be decrypted by the SoC, and (iii) an encrypted traffic stream that cannot be decrypted by the SoC. The intrusion detection system performs an action responsive to detecting the malware traffic. The action is performed toward preventing malicious activity otherwise caused by the malware traffic.