Timeout Management in Scalable Malware Detection Clusters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection systems face scalability issues with resource constraints in on-premises appliances and lack on-site deployment flexibility, particularly in managing network traffic and ensuring timely analysis operations, especially with increasing network activity.

Innovation Solution

A scalable threat detection system employing asynchronous or synchronous load balancing architectures with sensors and clusters that include timeout management units to monitor and adjust resource allocation dynamically, allowing for real-time re-enrollment and capacity adjustments to maintain efficient malware analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If on-premises malware detection appliances are used, then malware detection capability is provided, but resource constraints occur as network traffic increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidnetwork traffic handling capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments malware detection functionality into distributed sensors deployed throughout the network infrastructure. Each sensor handles local traffic analysis independently, allowing the system to scale with network growth without creating a single point of resource contention. This segmentation enables parallel processing of network traffic across multiple locations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimension appliance-based model to a multi-dimensional distributed sensor architecture. Sensors are placed at multiple network ingress points across different physical locations and hierarchical levels, adding spatial and organizational dimensions to the detection capability. This allows simultaneous handling of traffic from multiple sources without resource constraints at any single point.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If additional malware detection appliances are installed to handle increased traffic, then detection capacity increases, but capital outlay and network downtime increase

Engineering Contradiction:
Improvedetection capacityVSAvoiddeployment cost and complexity
Core Design Contradiction:
ProductivityVSEase of manufacture

Solution Approach 1:

The sensor architecture is designed to be universally deployable across various network infrastructure components. Sensors can be integrated into existing switches, routers, or standalone devices, allowing the system to leverage existing hardware investments. This multi-functionality enables capacity increases without requiring specialized new appliances, reducing capital outlay.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs dynamic sensor enrollment and capacity adjustment mechanisms. New sensors can be enrolled in the network incrementally as capacity needs arise, without requiring planned downtime for bulk installations. The load balancing architecture dynamically adapts to changing traffic patterns and sensor availability, allowing flexible capacity expansion that minimizes deployment disruption and cost.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If cloud-based malware detection is used, then resource scalability is achieved, but on-site deployment flexibility is lost

Engineering Contradiction:
Improveresource scalabilityVSAvoidon-site deployment flexibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system implements local quality by placing sensors at specific network locations where they can process traffic locally before forwarding results centrally. Each sensor maintains local state and decision-making capability, providing on-site deployment flexibility while the centralized coordination provides scalability. This hybrid approach allows sensitive local data to remain on-premises while leveraging centralized resources for complex analysis.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces a centralized coordination system that acts as an intermediary between distributed sensors and external cloud resources. This mediator manages sensor enrollment, coordinates analysis tasks, and handles load balancing, allowing sensors to maintain local autonomy while accessing scalable resources when needed. The intermediary layer enables both on-site flexibility and cloud-based scalability to coexist.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If timeout management is not implemented, then analysis operations may be incomplete, but system responsiveness deteriorates with increasing traffic

Engineering Contradiction:
Improveanalysis completenessVSAvoidanalysis latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic timeout monitoring and analysis completion checks across all sensors. Timeout mechanisms are systematically applied to ensure that no analysis operation exceeds predefined time thresholds, maintaining system responsiveness. This periodic enforcement prevents any single analysis task from monopolizing resources and degrading overall system performance.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The centralized coordination system receives feedback from sensors regarding analysis status and timeout conditions. This feedback loop enables real-time monitoring of analysis completeness and system responsiveness. When timeouts are detected or anticipated, the system can dynamically adjust resource allocation, prioritize critical analyses, or redirect traffic to maintain both completeness and responsiveness under varying load conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10671721B1Timeout management services
Publication Date: 2020.06.02 MAGENTA SECURITY HOLDINGS LLC
  • US10671721B1 patent drawing
  • US10671721B1 patent drawing
  • US10671721B1 patent drawing

AI summary

A scalable, threat detection system features computing nodes including a first computing node and a second computing node operating as a cluster. Each computing node features an analysis coordinator and an object analyzer. The analysis coordinator is configured to conduct an analysis of metadata associated with a suspicious object that is to be analyzed for malware, where the metadata being received from a remotely located network device and to store a portion of the metadata within a data store. The object analyzer is configured to retrieve the portion of the metadata from the data store, monitor a duration of retention of the metadata in the data store, and determine whether a timeout event has occurred for the object associated with the metadata based on retention of the metadata within the data store that exceeds a timeout value included as part of the metadata associated with the suspicious object for malware.