Unified Threat Management via Self-Organizing Map Pattern Recognition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security systems face challenges in providing comprehensive and efficient protection against diverse threats such as viruses, hacker attacks, spyware, phishing, and unauthorized intrusions, often requiring substantial processing resources and leading to operational complexity, while also struggling with false alarms and high maintenance in intrusion detection systems.
Innovation Solution
A flow processing facility utilizing artificial neurons, such as a self-organizing map, to process data flows and recognize patterns relevant to various threats, enabling unified threat management by integrating disparate threat management methods into a single architecture for intrusion detection, prevention, and content inspection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If unified threat management suite is implemented to provide comprehensive protection against multiple threats, then security coverage is improved, but processing resource consumption increases
Solution Approach 1:
The patent combines multiple standalone security applications (firewall, intrusion detection, antivirus, spam filtering) into a single unified threat management system. This merging allows the system to process multiple threat types simultaneously through shared infrastructure, reducing overall processing resource consumption while maintaining comprehensive security coverage.
Solution Approach 2:
The unified threat management system is designed to perform multiple security functions through a single platform that can handle different threat types (network threats, application threats, malware) using common processing resources. This multi-functionality eliminates the need for separate dedicated resources for each security application.
2Reliability
If software firewall is installed on server to protect against threats, then security protection is improved, but processing resource consumption increases
Solution Approach 1:
The patent introduces a dedicated network device as an intermediary firewall system that handles security filtering before traffic reaches the server. This mediator absorbs the processing burden of threat filtering, allowing the server to maintain its primary functions while still receiving protected traffic, thus reducing the server's processing resource consumption.
3Reliability
If dedicated network device firewall is used to protect against threats, then security protection is improved, but operational complexity increases
Solution Approach 1:
The patent consolidates firewall functionality into a dedicated network device that is integrated into the network infrastructure. This merging of security functions into a single point of control simplifies operational management compared to distributing firewall software across multiple servers, reducing operational complexity while maintaining security protection.
4Measurement precision
If intrusion detection system is implemented to detect threats, then threat detection capability is improved, but false alarms increase
Solution Approach 1:
The unified threat management system incorporates feedback mechanisms where detection results from multiple security applications are cross-validated. When multiple security modules independently detect the same threat pattern, the system confirms the detection, reducing false alarms while maintaining high threat detection capability.
Solution Approach 2:
The system uses a universal detection platform that applies consistent analysis methods across multiple threat types. This unified approach allows the system to learn from patterns across different threat categories, improving detection accuracy and reducing false alarms through shared intelligence.
Data Source
Figure 1
Figure 2
Figure 3~3A
AI summary
A flow processing facility using a set of artificial neurons for pattern recognition, such as a self-organizing map, providing security and protection to a computer system which supports unified threat management based at least in part on patterns relevant to a variety of types of threats that relate to computer systems and networks. Flow processing for switching, security, and other network applications, including a facility that processes a data flow to address patterns relevant to a variety of conditions are directed at internal network security, virtualization, and web connection security. A flow processing facility for inspecting payloads of network traffic packets detects security threats and intrusions across accessible layers of the IP-stack by applying content matching and behavioral anomaly detection techniques based on regular expression matching and self-organizing maps. Exposing threats and intrusions within packet payload at or near real-time rates enhances network security from both external and internal sources while ensuring security policy is rigorously applied to data and system resources. Intrusion Detection and Protection (IDP) is provided by a flow processing facility that processes a data flow to address patterns relevant to a variety of types of network and data integrity threats that relate to computer systems, including computer networks.