Network Traffic Segregation for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security systems face challenges in effectively monitoring and enforcing security policies due to the diversity and unpredictability of human and computer interactions, making it difficult to detect and prevent malware intrusions.

Innovation Solution

Implementing a technology that segregates computer or communications traffic into distinct classifications based on security values, such as user participation, allowing for the application of detection and enforcement policies to determine and manage appropriate or inappropriate traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic monitoring is performed on all communications without segregation, then comprehensive security coverage is achieved, but detection precision deteriorates due to traffic diversity and unpredictability

Engineering Contradiction:
Improvesecurity coverageVSAvoiddetection precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments network traffic into multiple classification groups based on security values and user participation characteristics. By dividing the monolithic traffic stream into categorized segments, the system achieves both comprehensive coverage (all traffic is classified) and improved detection precision (each segment can be monitored with targeted policies). This directly resolves the contradiction by making traffic diversity manageable through systematic categorization.

Inventive Principle:
Principle #1Segmentation

2Reliability

If strict security enforcement policies are applied to all traffic, then security reliability is improved, but system adaptability deteriorates due to inability to distinguish between different traffic types

Engineering Contradiction:
Improvesecurity enforcementVSAvoidtraffic policy adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing different security policies tailored to specific traffic classification groups. Instead of uniform enforcement across all traffic, the system assigns appropriate detection and enforcement policies to each category based on its security characteristics. This allows strict enforcement where needed while maintaining adaptability for different traffic types, resolving the contradiction between reliability and adaptability.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If traffic segregation into multiple classifications is implemented, then detection precision is improved by making suspicious behaviors more detectable, but device complexity increases

Engineering Contradiction:
Improvesuspicious behavior detectionVSAvoidtraffic classification complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing traffic classification groups and assigning detection/enforcement policies to each category before actual security monitoring begins. This upfront organization of traffic into security-based categories simplifies the ongoing detection process, as the system only needs to apply predefined policies to pre-classified traffic rather than making complex real-time decisions, thus improving detection precision while managing complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7698548B2Communications traffic segregation for security purposes
Publication Date: 2010.04.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7698548B2 patent drawing
  • US7698548B2 patent drawing
  • US7698548B2 patent drawing

AI summary

Technology for applying a communications traffic security policy in which a distinct communications traffic flow is segregated based upon a security value; whereby the communications traffic security policy include one or both of a detection and an enforcement policy. The detection policy may include determining whether the segregated communications traffic flow involves malware; and, the enforcement policy may include a malware policy.