Network Traffic Segregation for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer security systems face challenges in effectively monitoring and enforcing security policies due to the diversity and unpredictability of human and computer interactions, making it difficult to detect and prevent malware intrusions.
Innovation Solution
Implementing a technology that segregates computer or communications traffic into distinct classifications based on security values, such as user participation, allowing for the application of detection and enforcement policies to determine and manage appropriate or inappropriate traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic monitoring is performed on all communications without segregation, then comprehensive security coverage is achieved, but detection precision deteriorates due to traffic diversity and unpredictability
Solution Approach 1:
The patent segments network traffic into multiple classification groups based on security values and user participation characteristics. By dividing the monolithic traffic stream into categorized segments, the system achieves both comprehensive coverage (all traffic is classified) and improved detection precision (each segment can be monitored with targeted policies). This directly resolves the contradiction by making traffic diversity manageable through systematic categorization.
2Reliability
If strict security enforcement policies are applied to all traffic, then security reliability is improved, but system adaptability deteriorates due to inability to distinguish between different traffic types
Solution Approach 1:
The patent applies local quality by implementing different security policies tailored to specific traffic classification groups. Instead of uniform enforcement across all traffic, the system assigns appropriate detection and enforcement policies to each category based on its security characteristics. This allows strict enforcement where needed while maintaining adaptability for different traffic types, resolving the contradiction between reliability and adaptability.
3Measurement precision
If traffic segregation into multiple classifications is implemented, then detection precision is improved by making suspicious behaviors more detectable, but device complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing traffic classification groups and assigning detection/enforcement policies to each category before actual security monitoring begins. This upfront organization of traffic into security-based categories simplifies the ongoing detection process, as the system only needs to apply predefined policies to pre-classified traffic rather than making complex real-time decisions, thus improving detection precision while managing complexity.
Data Source
AI summary
Technology for applying a communications traffic security policy in which a distinct communications traffic flow is segregated based upon a security value; whereby the communications traffic security policy include one or both of a detection and an enforcement policy. The detection policy may include determining whether the segregated communications traffic flow involves malware; and, the enforcement policy may include a malware policy.


