Trusted Device Network Traffic Breach Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively detect data breaches in network-connected computer systems, leading to prolonged exposure of sensitive data and delayed protective actions.

Innovation Solution

A computer-implemented method using a trusted secure computing device to store network traffic, generate a copy of data, identify information about network attacks, create a signature for attack detection, and implement protective measures for compromised data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If network traffic is monitored and analyzed in real-time to detect data breaches, then detection speed is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvedetection delayVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by storing network traffic data and generating copies of distributed data before actual breach detection is needed. This allows the detection mechanism to work with pre-prepared data, reducing detection delay without requiring complex real-time processing infrastructure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention creates copies of data distributed across the network and stores network traffic copies at a trusted secure computing device. This copying approach enables analysis of breach patterns without compromising the original system's performance or requiring direct interference with live traffic flows.

Inventive Principle:
Principle #26Copying

2Measurement precision

If comprehensive network traffic is stored for analysis, then detection accuracy is improved, but storage requirements and data management complexity increase

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the necessary information about network attacks from the copied data, rather than storing and analyzing all raw network traffic. This extraction approach identifies specific attack patterns and characteristics, improving detection accuracy while minimizing the volume of data that needs to be managed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention segments the large volume of network traffic data into manageable portions, storing at least a portion of network traffic rather than complete datasets. This segmentation allows for efficient storage and analysis of critical breach-related information without overwhelming storage requirements.

Inventive Principle:
Principle #1Segmentation

3Reliability

If signature-based detection is implemented to identify network attacks, then detection reliability is improved, but the system becomes more complex and harder to maintain

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsignature management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system generates attack signatures automatically from identified network attack patterns rather than requiring manual creation and maintenance of signature databases. This self-service approach improves detection reliability by using actual observed attack characteristics while reducing the complexity of signature management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention implements a feedback mechanism where identified network attacks are used to generate new signatures that improve future detection. This closed-loop approach continuously refines detection reliability based on actual breach data without requiring external intervention for signature updates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11658996B2Historic data breach detection
Publication Date: 2023.05.23 BRITISH TELECOM PLC
  • US11658996B2 patent drawing
  • US11658996B2 patent drawing
  • US11658996B2 patent drawing

AI summary

A computer implemented method to detect a data breach in a network-connected computing system, the method including storing, at a trusted secure computing device, at least a portion of network traffic communicated with the computer system; the computing device generating a copy of data distributed across a network; the computing device identifying information about the network attack stored in the copy of the data; the computing device generating a signature for the network attack based on the information about the network attack, the signature including rules for identifying the network attack in network traffic; and identifying an occurrence of the network attack in the stored network traffic based on the signature.