Threat Response Platform for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems lack an effective mechanism to differentiate between malware-induced suspicious activity and false positives, often failing to provide timely and accurate responses to potential threats, especially in non-inline security modes.

Innovation Solution

A threat response platform that facilitates communication between non-inline and inline security programs, utilizing an active correlation system to gather and analyze data from client devices and other sources, and optionally deploying a temporary agent to identify potential indications of compromise, while also providing a Turing test to verify human involvement in network connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If non-inline security programs are used to monitor suspicious activity, then the ability to detect potential malware threats is improved, but the ability to block connections or stop suspicious activity is lost

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse effectiveness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a threat response platform as an intermediary component that bridges non-inline security programs and inline security programs. This mediator receives event reports from non-inline programs, performs correlation analysis, and generates response recommendations that can be implemented by inline security programs, thereby combining the detection strengths of non-inline programs with the blocking capabilities of inline programs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If inline security programs are used to block connections, then the ability to prevent malware communication is improved, but the ability to differentiate between malware and legitimate traffic is reduced

Engineering Contradiction:
Improveconnection blocking capabilityVSAvoidthreat differentiation accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements a feedback mechanism where the threat response platform continuously monitors event reports, analyzes correlation data, and adjusts response recommendations based on the effectiveness of previous actions. This feedback loop enables the system to learn from actual outcomes and improve its ability to differentiate between malware and legitimate traffic over time, reducing false positives while maintaining blocking effectiveness.

Inventive Principle:
Principle #23Feedback

3Device complexity

If security programs operate independently without communication, then the system complexity is reduced, but the ability to provide comprehensive security responses is limited

Engineering Contradiction:
Improvesystem architecture simplicityVSAvoidsecurity response capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The threat response platform is designed as a universal system that can work with multiple types of security programs (both inline and non-inline) and perform multiple functions including event report reception, correlation analysis, response generation, and implementation coordination. This multi-functional design enables comprehensive security responses without requiring completely separate independent systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3069473B1System and method of protecting client computers
Publication Date: 2020.12.30 PROOFPOINT INC
  • EP3069473B1 patent drawingFigure 1
  • EP3069473B1 patent drawingFigure 2
  • EP3069473B1 patent drawingFigure 3

AI summary

A threat response platform to act as a bridge between non-inline security programs and inline security programs. The threat response platform receives event reports, relating to client devices, from the non-inline security programs and creates incident reports for a user. The incident reports describe the event report and also additional data gathered by an active correlation system of the threat response platform. The active correlation system automatically gathers various types of data that are potentially useful to a user in determining whether the reported event is an incidence of malware operating on the client device or a false positive. The active correlation system places a temporary agent on the client device to identify indications of compromise.