Threat Response Platform for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems lack an effective mechanism to differentiate between human-initiated and automated malware connections, and struggle to efficiently manage and respond to potential malware incidents across client devices within a network.

Innovation Solution

A threat response platform that facilitates communication between non-inline and inline security programs, utilizing an active correlation system to gather and analyze data from client devices, firewalls, and other sources, and employs a Turing test to verify human authorization for connections, while providing incident reports and automated responses to suspected malware threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If non-inline security programs are used to detect suspicious activity, then detection capability is improved, but the ability to block connections is insufficient

Engineering Contradiction:
Improvedetection capabilityVSAvoidconnection blocking capability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces an intermediary component that bridges non-inline security programs and inline security programs. This intermediary receives event reports from non-inline detectors, processes them through correlation systems, and transmits blocking rules to inline security programs, thereby enabling the detection capabilities of non-inline programs to be effectively utilized for connection blocking.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines the strengths of both non-inline and inline security programs into a unified system. Non-inline programs provide broad detection capabilities while inline programs provide enforcement capabilities, and the patent merges their functions through a correlation system that integrates event reporting, analysis, and blocking rule generation into a single cohesive security architecture.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If inline security programs block connections based on suspicious activity, then connection protection is improved, but false positives increase

Engineering Contradiction:
Improveconnection protectionVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements preliminary action by requiring multiple indicators of compromise (IOCs) to be present before triggering a block. The correlation system performs preliminary analysis of event reports, gathering additional data and evaluating multiple IOCs before generating blocking rules, thereby reducing false positives while maintaining protection effectiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the correlation system continuously monitors and evaluates event reports, adjusting blocking rules based on the presence and combination of multiple IOCs. This feedback loop allows the system to refine its blocking decisions, reducing false positives while maintaining high protection effectiveness.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If multiple IOCs are required to confirm malware infection, then accuracy is improved, but response time is delayed

Engineering Contradiction:
Improveinfection confirmation accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies dynamics by making the IOC requirement flexible rather than static. The correlation system dynamically adjusts the number and type of IOCs required based on the severity and characteristics of the detected threat. For high-severity threats, fewer IOCs may trigger immediate blocking, while lower-severity threats require more IOCs for confirmation, thereby balancing accuracy and response time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The correlation system performs preliminary gathering and evaluation of IOCs as events are detected, rather than waiting for a fixed number of IOCs to accumulate. This preliminary action allows the system to proactively identify threats and initiate blocking procedures when sufficient evidence is available, reducing response time while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If agent programs are placed on client devices to collect IOC data, then data gathering capability is improved, but device security risk increases

Engineering Contradiction:
Improvedata gathering capabilityVSAvoiddevice security risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements the disposable principle by using temporary agent programs that are deployed to client devices solely for the purpose of collecting IOC data and then automatically removed after completing their task. These short-lived agents minimize the security risk of having persistent code on client devices while maintaining the capability to gather necessary data for malware detection.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The correlation system acts as an intermediary that coordinates the deployment and removal of agent programs. It manages the lifecycle of these agents, ensuring they are deployed only when necessary, perform their data gathering function, and are subsequently removed, thereby minimizing the security risk while maintaining data gathering capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12013936B2System and method of protecting client computers
Publication Date: 2024.06.18 GOLDMAN SACHS BANK USA
  • US12013936B2 patent drawing
  • US12013936B2 patent drawing
  • US12013936B2 patent drawing

AI summary

A threat response platform to act as a bridge between non-inline security programs and inline security programs. The threat response platform receives event reports, relating to client devices, from the non-inline security programs and creates incident reports for a user. The incident reports describe the event report and also additional data gathered by an active correlation system of the threat response platform. The active correlation system automatically gathers various types of data that are potentially useful to a user in determining whether the reported event is an incidence of malware operating on the client device or a false positive. The active correlation system places a temporary agent on the client device to identify indications of compromise.