Trusted Device Network Traffic Breach Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively detect data breaches in network-connected computer systems, leading to prolonged exposure of sensitive data and delayed protective actions.
Innovation Solution
A computer-implemented method using a trusted secure computing device to store network traffic, generate a copy of data, identify information about network attacks, create a signature for attack detection, and implement protective measures for compromised data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If network traffic is monitored and analyzed in real-time to detect data breaches, then detection speed is improved, but system complexity and resource consumption increase
Solution Approach 1:
The system performs preliminary actions by storing network traffic data and generating copies of distributed data before actual breach detection is needed. This allows the detection mechanism to work with pre-prepared data, reducing detection delay without requiring complex real-time processing infrastructure.
Solution Approach 2:
The invention creates copies of data distributed across the network and stores network traffic copies at a trusted secure computing device. This copying approach enables analysis of breach patterns without compromising the original system's performance or requiring direct interference with live traffic flows.
2Measurement precision
If comprehensive network traffic is stored for analysis, then detection accuracy is improved, but storage requirements and data management complexity increase
Solution Approach 1:
The system extracts only the necessary information about network attacks from the copied data, rather than storing and analyzing all raw network traffic. This extraction approach identifies specific attack patterns and characteristics, improving detection accuracy while minimizing the volume of data that needs to be managed.
Solution Approach 2:
The invention segments the large volume of network traffic data into manageable portions, storing at least a portion of network traffic rather than complete datasets. This segmentation allows for efficient storage and analysis of critical breach-related information without overwhelming storage requirements.
3Reliability
If signature-based detection is implemented to identify network attacks, then detection reliability is improved, but the system becomes more complex and harder to maintain
Solution Approach 1:
The system generates attack signatures automatically from identified network attack patterns rather than requiring manual creation and maintenance of signature databases. This self-service approach improves detection reliability by using actual observed attack characteristics while reducing the complexity of signature management.
Solution Approach 2:
The invention implements a feedback mechanism where identified network attacks are used to generate new signatures that improve future detection. This closed-loop approach continuously refines detection reliability based on actual breach data without requiring external intervention for signature updates.
Data Source
AI summary
A computer implemented method to detect a data breach in a network-connected computing system, the method including storing, at a trusted secure computing device, at least a portion of network traffic communicated with the computer system; the computing device generating a copy of data distributed across a network; the computing device identifying information about the network attack stored in the copy of the data; the computing device generating a signature for the network attack based on the information about the network attack, the signature including rules for identifying the network attack in network traffic; and identifying an occurrence of the network attack in the stored network traffic based on the signature.


