Unified Threat Management System for Unknown Compromised Node Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional digital security technologies rely on threat-specific signatures, making it difficult to detect unknown threats such as 'zero-day' exploits and new computer viruses, as signatures for these threats are difficult to create, leading to vulnerabilities that can go undetected.

Innovation Solution

A method that involves monitoring network traffic for characteristic emanations from compromised computing systems, using a Unified Threat Management System (UTMS) to recognize patterns in network packets before and after a known threat is introduced, creating meta-expressions to detect compromised systems independently of the threat type, and taking responsive actions such as cloaking the compromised node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional digital security technologies use threat-specific signatures for detection, then detection accuracy for known threats is improved, but the ability to detect unknown threats deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs self-learning by automatically analyzing network traffic patterns and generating detection rules without requiring manual signature creation. The UTMS observes compromised system behavior and autonomously creates meta-expressions for detecting similar threats, eliminating the need for external signature updates

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transforms detection from signature-matching to behavioral parameter analysis. Instead of comparing fixed signatures, the UTMS monitors dynamic network traffic parameters such as packet timing, data flow patterns, and communication protocols to identify compromised systems based on their operational characteristics

Inventive Principle:
Principle #35Parameter changes

2Reliability

If digital security technologies rely on a priori knowledge of specific threats, then detection of known threats is improved, but detection of new threats deteriorates

Engineering Contradiction:
Improvedetection reliabilityVSAvoidthreat coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary learning by continuously monitoring and analyzing network traffic patterns during normal operation. Before new threats emerge, the UTMS has already established baseline behavioral models that enable it to recognize deviations indicating compromise, regardless of whether the specific threat was previously known

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where detection results and analyzed traffic patterns continuously refine the behavioral models. The UTMS learns from each detected incident and updates its detection rules, creating a self-improving system that adapts to new threat patterns while maintaining reliability for known threats

Inventive Principle:
Principle #23Feedback

3Productivity

If signature-based detection methods are used, then detection speed for known threats is improved, but the ability to respond to unknown threats deteriorates

Engineering Contradiction:
Improvedetection speedVSAvoidunknown threat detection
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system automatically generates detection rules by analyzing traffic patterns in real-time without requiring manual intervention or signature database updates. This self-learning capability enables the UTMS to detect both known and unknown threats at high speed by comparing observed behavior against dynamically created behavioral models

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10862923B2System and method for detecting a compromised computing system
Publication Date: 2020.12.08 SECURESKY INC
  • US10862923B2 patent drawing
  • US10862923B2 patent drawing
  • US10862923B2 patent drawing

AI summary

A digital security threat management system is disclosed. The system detects the presence of a computing system, on a network, that has been compromised by an undetected and/or unknown digital security threat. The digital security threat management system recognizes characteristic emanations from a computer system that has been compromised. Because the characteristic emanations that result from a known threat can be the same as the characteristic emanations that result from an undetected and/or unknown threat, the digital security threat management system can learn to detect a computing system that has been compromised by an unknown threat if the security threat management system recognizes characteristic emanations from a previous attack, based on a known threat, of the computing system. In this way, the system can detect the presence of a compromised computing system, even if the cause of the compromise remains undetected and/or unknown. Appropriate remedial action may be taken upon detection.