Network Terminal Infection Risk Identification System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques fail to appropriately specify terminals suspected of infection or likely to be infected in the future, especially in network attacks involving malware, as they do not effectively identify secondary infection routes after detecting an infected terminal.
Innovation Solution
A specifying system and method that includes a configuration information storage device for network terminals and a specifying device with a state specifying unit and an infection specifying unit, which uses connection information to identify terminals likely to be infected based on detection information from security devices, determining infection risk scores and specifying candidates for future infections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security devices detect and shut down infected terminals, then the detected terminal is isolated from further infection, but other infected terminals that were not detected continue to spread malware through the network
Solution Approach 1:
The system performs preliminary analysis of connection information and attack patterns before infection spreads further. By examining network connection data and terminal states in advance, the system identifies potential infection routes and suspects terminals proactively, rather than waiting for detection after infection occurs.
Solution Approach 2:
The system introduces an intermediary analysis layer that processes connection information between terminals and security device detections. This intermediary component infers hidden infection states by analyzing network topology and communication patterns, bridging the gap between detected and undetected terminals.
2Measurement precision
If the system monitors all terminals in the network for infection, then detection coverage is improved, but the complexity of analyzing network connections and terminal states increases significantly
Solution Approach 1:
The system applies different analysis methods to different parts of the network based on local characteristics. Connection information and terminal states are analyzed with appropriate depth according to risk levels, network position, and detected infection patterns, rather than applying uniform complex analysis to all terminals.
Solution Approach 2:
The analysis process is segmented into multiple stages: collecting connection information, detecting infected terminals, inferring infection routes, and identifying suspect terminals. Each segment handles a specific aspect of the problem, reducing overall system complexity while maintaining comprehensive detection coverage.
3Reliability
If the system identifies all potential infection routes and suspect terminals, then network security is enhanced, but the time required to process and analyze infection data increases
Solution Approach 1:
The system performs partial analysis focused on the most critical aspects: connection information relevant to detected infections and terminals on direct infection routes. Rather than exhaustively analyzing all possible infection paths, the system concentrates computational resources on high-probability suspects and immediate threats.
Solution Approach 2:
Connection information and terminal states are pre-collected and organized before infection analysis is needed. This preliminary data preparation reduces processing time during actual infection detection events, allowing rapid identification of suspect terminals when security incidents occur.
Data Source
AI summary
A specifying device receives detection information from a security device that detects hacking into a network or an activity of a terminal related to infection, and specifies a state of the terminal from information of the terminal and content of activity of the terminal included in the detection information. The specifying device specifies, when specifying that the terminal is in the state of being infected with malware, a terminal that may be infected before performing the content of the activity of the terminal included in the detection information based on connection information stored in a configuration information storage device, and specifies a terminal located on a route, along which the infected terminal is likely to be used for hacking or for infection of the terminal in the future, as a candidate for an infected terminal likely to be infected.


