Unified Threat Management via Self-Organizing Map Pattern Recognition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems face challenges in providing comprehensive and efficient protection against diverse threats such as viruses, hacker attacks, spyware, phishing, and unauthorized intrusions, often requiring substantial processing resources and leading to operational complexity, while also struggling with false alarms and high maintenance in intrusion detection systems.

Innovation Solution

A flow processing facility utilizing artificial neurons, such as a self-organizing map, to process data flows and recognize patterns relevant to various threats, enabling unified threat management by integrating disparate threat management methods into a single architecture for intrusion detection, prevention, and content inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unified threat management suite is implemented to provide comprehensive protection against multiple threats, then security coverage is improved, but processing resource consumption increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent combines multiple standalone security applications (firewall, intrusion detection, antivirus, spam filtering) into a single unified threat management system. This merging allows the system to process multiple threat types simultaneously through shared infrastructure, reducing overall processing resource consumption while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified threat management system is designed to perform multiple security functions through a single platform that can handle different threat types (network threats, application threats, malware) using common processing resources. This multi-functionality eliminates the need for separate dedicated resources for each security application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If software firewall is installed on server to protect against threats, then security protection is improved, but processing resource consumption increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a dedicated network device as an intermediary firewall system that handles security filtering before traffic reaches the server. This mediator absorbs the processing burden of threat filtering, allowing the server to maintain its primary functions while still receiving protected traffic, thus reducing the server's processing resource consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dedicated network device firewall is used to protect against threats, then security protection is improved, but operational complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent consolidates firewall functionality into a dedicated network device that is integrated into the network infrastructure. This merging of security functions into a single point of control simplifies operational management compared to distributing firewall software across multiple servers, reducing operational complexity while maintaining security protection.

Inventive Principle:
Principle #5Merging (Combining)

4Measurement precision

If intrusion detection system is implemented to detect threats, then threat detection capability is improved, but false alarms increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidfalse alarms
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The unified threat management system incorporates feedback mechanisms where detection results from multiple security applications are cross-validated. When multiple security modules independently detect the same threat pattern, the system confirms the detection, reducing false alarms while maintaining high threat detection capability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system uses a universal detection platform that applies consistent analysis methods across multiple threat types. This unified approach allows the system to learn from patterns across different threat categories, improving detection accuracy and reducing false alarms through shared intelligence.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2432188B1Systems and methods for processing data flows
Publication Date: 2016.04.20 GEN DIGITAL INC
  • EP2432188B1 patent drawingFigure 1
  • EP2432188B1 patent drawingFigure 2
  • EP2432188B1 patent drawingFigure 3~3A

AI summary

A flow processing facility using a set of artificial neurons for pattern recognition, such as a self-organizing map, providing security and protection to a computer system which supports unified threat management based at least in part on patterns relevant to a variety of types of threats that relate to computer systems and networks. Flow processing for switching, security, and other network applications, including a facility that processes a data flow to address patterns relevant to a variety of conditions are directed at internal network security, virtualization, and web connection security. A flow processing facility for inspecting payloads of network traffic packets detects security threats and intrusions across accessible layers of the IP-stack by applying content matching and behavioral anomaly detection techniques based on regular expression matching and self-organizing maps. Exposing threats and intrusions within packet payload at or near real-time rates enhances network security from both external and internal sources while ensuring security policy is rigorously applied to data and system resources. Intrusion Detection and Protection (IDP) is provided by a flow processing facility that processes a data flow to address patterns relevant to a variety of types of network and data integrity threats that relate to computer systems, including computer networks.