Threat Response Platform for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security systems lack an effective mechanism to differentiate between human-initiated and automated malware connections, and struggle to efficiently manage and respond to potential malware incidents across client devices within a network.
Innovation Solution
A threat response platform that facilitates communication between non-inline and inline security programs, utilizing an active correlation system to gather and analyze data from client devices, firewalls, and other sources, and employs a Turing test to verify human authorization for connections, while providing incident reports and automated responses to suspected malware threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If non-inline security programs are used to detect suspicious activity, then detection capability is improved, but the ability to block connections is insufficient
Solution Approach 1:
The patent introduces an intermediary component that bridges non-inline security programs and inline security programs. This intermediary receives event reports from non-inline detectors, processes them through correlation systems, and transmits blocking rules to inline security programs, thereby enabling the detection capabilities of non-inline programs to be effectively utilized for connection blocking.
Solution Approach 2:
The patent combines the strengths of both non-inline and inline security programs into a unified system. Non-inline programs provide broad detection capabilities while inline programs provide enforcement capabilities, and the patent merges their functions through a correlation system that integrates event reporting, analysis, and blocking rule generation into a single cohesive security architecture.
2Reliability
If inline security programs block connections based on suspicious activity, then connection protection is improved, but false positives increase
Solution Approach 1:
The patent implements preliminary action by requiring multiple indicators of compromise (IOCs) to be present before triggering a block. The correlation system performs preliminary analysis of event reports, gathering additional data and evaluating multiple IOCs before generating blocking rules, thereby reducing false positives while maintaining protection effectiveness.
Solution Approach 2:
The patent incorporates feedback mechanisms where the correlation system continuously monitors and evaluates event reports, adjusting blocking rules based on the presence and combination of multiple IOCs. This feedback loop allows the system to refine its blocking decisions, reducing false positives while maintaining high protection effectiveness.
3Measurement precision
If multiple IOCs are required to confirm malware infection, then accuracy is improved, but response time is delayed
Solution Approach 1:
The patent applies dynamics by making the IOC requirement flexible rather than static. The correlation system dynamically adjusts the number and type of IOCs required based on the severity and characteristics of the detected threat. For high-severity threats, fewer IOCs may trigger immediate blocking, while lower-severity threats require more IOCs for confirmation, thereby balancing accuracy and response time.
Solution Approach 2:
The correlation system performs preliminary gathering and evaluation of IOCs as events are detected, rather than waiting for a fixed number of IOCs to accumulate. This preliminary action allows the system to proactively identify threats and initiate blocking procedures when sufficient evidence is available, reducing response time while maintaining accuracy.
4Productivity
If agent programs are placed on client devices to collect IOC data, then data gathering capability is improved, but device security risk increases
Solution Approach 1:
The patent implements the disposable principle by using temporary agent programs that are deployed to client devices solely for the purpose of collecting IOC data and then automatically removed after completing their task. These short-lived agents minimize the security risk of having persistent code on client devices while maintaining the capability to gather necessary data for malware detection.
Solution Approach 2:
The correlation system acts as an intermediary that coordinates the deployment and removal of agent programs. It manages the lifecycle of these agents, ensuring they are deployed only when necessary, perform their data gathering function, and are subsequently removed, thereby minimizing the security risk while maintaining data gathering capability.
Data Source
AI summary
A threat response platform to act as a bridge between non-inline security programs and inline security programs. The threat response platform receives event reports, relating to client devices, from the non-inline security programs and creates incident reports for a user. The incident reports describe the event report and also additional data gathered by an active correlation system of the threat response platform. The active correlation system automatically gathers various types of data that are potentially useful to a user in determining whether the reported event is an incidence of malware operating on the client device or a false positive. The active correlation system places a temporary agent on the client device to identify indications of compromise.


