Threat Response Platform for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security systems lack an effective mechanism to differentiate between malware-induced suspicious activity and false positives, often failing to provide timely and accurate responses to potential threats, especially in non-inline security modes.
Innovation Solution
A threat response platform that facilitates communication between non-inline and inline security programs, utilizing an active correlation system to gather and analyze data from client devices and other sources, and optionally deploying a temporary agent to identify potential indications of compromise, while also providing a Turing test to verify human involvement in network connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If non-inline security programs are used to monitor suspicious activity, then the ability to detect potential malware threats is improved, but the ability to block connections or stop suspicious activity is lost
Solution Approach 1:
The patent introduces a threat response platform as an intermediary component that bridges non-inline security programs and inline security programs. This mediator receives event reports from non-inline programs, performs correlation analysis, and generates response recommendations that can be implemented by inline security programs, thereby combining the detection strengths of non-inline programs with the blocking capabilities of inline programs.
2Reliability
If inline security programs are used to block connections, then the ability to prevent malware communication is improved, but the ability to differentiate between malware and legitimate traffic is reduced
Solution Approach 1:
The patent implements a feedback mechanism where the threat response platform continuously monitors event reports, analyzes correlation data, and adjusts response recommendations based on the effectiveness of previous actions. This feedback loop enables the system to learn from actual outcomes and improve its ability to differentiate between malware and legitimate traffic over time, reducing false positives while maintaining blocking effectiveness.
3Device complexity
If security programs operate independently without communication, then the system complexity is reduced, but the ability to provide comprehensive security responses is limited
Solution Approach 1:
The threat response platform is designed as a universal system that can work with multiple types of security programs (both inline and non-inline) and perform multiple functions including event report reception, correlation analysis, response generation, and implementation coordination. This multi-functional design enables comprehensive security responses without requiring completely separate independent systems for each function.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A threat response platform to act as a bridge between non-inline security programs and inline security programs. The threat response platform receives event reports, relating to client devices, from the non-inline security programs and creates incident reports for a user. The incident reports describe the event report and also additional data gathered by an active correlation system of the threat response platform. The active correlation system automatically gathers various types of data that are potentially useful to a user in determining whether the reported event is an incidence of malware operating on the client device or a false positive. The active correlation system places a temporary agent on the client device to identify indications of compromise.