Whitelist Network Traffic Detection for Insider Threats
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security systems struggle to detect and prevent insider leaks and encrypted or obfuscated data leaks due to their reliance on blacklists and inability to differentiate between human and automated network traffic, leading to high false-positive rates and failure to identify non-browser web applications.
Innovation Solution
A method and system that utilize a whitelist-based approach to detect security threats and undesirable computer files by analyzing network traffic for timing and formatting anomalies, generating alerts for irregular patterns, and associating these with specific applications, while also measuring unconstrained outbound bandwidth to identify potential information leaks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security systems use blacklists to detect threats, then they can identify known malicious patterns, but they produce high false-positive rates and cannot detect encrypted or obfuscated data leaks
Solution Approach 1:
The patent inverts the conventional blacklist approach by implementing a whitelist-based system that defines legitimate traffic patterns. Instead of trying to identify and block all known threats, the system establishes what normal traffic should look like and flags deviations from these patterns. This inversion allows the system to detect previously undetectable threats including encrypted data leaks while significantly reducing false positives, as the whitelist provides a reliable baseline for legitimate activity.
Solution Approach 2:
The patent changes the detection parameters from static signature matching to dynamic behavioral analysis. By monitoring timing patterns, message formatting, frequency of communication, and other temporal parameters, the system can identify anomalous behavior that indicates potential threats. This parameter change enables detection of encrypted and obfuscated traffic by focusing on behavioral characteristics rather than content analysis, thereby improving reliability without increasing false positives.
2Reliability
If security systems monitor all network traffic for threats, then they can detect potential security incidents, but they cannot differentiate between human and automated traffic leading to high false positives
Solution Approach 1:
The patent introduces temporal parameters as key differentiation factors between human and automated traffic. By analyzing timing patterns such as inter-message intervals, communication frequency, and rhythmic regularity, the system can distinguish human-operated applications from automated bots. Human traffic exhibits more variable and less predictable timing patterns, while automated traffic shows more regular, programmed intervals. This parameter-based differentiation significantly improves measurement precision in threat detection.
Solution Approach 2:
The system implements feedback mechanisms that continuously learn from observed traffic patterns. By monitoring and adapting to the behavioral characteristics of legitimate applications over time, the system refines its understanding of what constitutes normal human versus automated traffic. This feedback loop enables the system to improve its differentiation capabilities dynamically, reducing false positives while maintaining reliable threat detection.
3Object-affected harmful factors
If conventional systems rely on blacklists, then they can block known malicious files, but they fail to identify non-browser web applications and encrypted data leaks
Solution Approach 1:
The patent inverts the detection approach by using whitelists to define legitimate web application behavior rather than blacklists to block known malware. By establishing baseline patterns for legitimate web traffic including timing, formatting, and communication protocols, the system can identify deviations that indicate non-browser applications or encrypted data leaks. This inversion provides adaptability to detect unknown threats while maintaining the ability to block known malicious files through pattern deviation detection.
Solution Approach 2:
The patent creates a universal detection framework that can identify multiple types of threats using the same behavioral analysis mechanisms. The system's timing and formatting analysis capabilities apply universally across different threat types including non-browser web applications, encrypted data leaks, and traditional malware. This multi-functional approach enhances adaptability by using a single versatile detection system rather than separate specialized systems for each threat type.
4Measurement precision
If security systems analyze detailed network traffic patterns, then they can identify specific applications and threats, but they increase system complexity and processing overhead
Solution Approach 1:
The patent focuses analysis on a selective set of temporal parameters such as timing intervals, message frequency, and formatting patterns rather than attempting to analyze all aspects of network traffic. By changing the parameters under analysis to these specific temporal characteristics, the system achieves high application identification accuracy without requiring complex analysis of every traffic attribute. This parameter selection reduces processing overhead while maintaining precision in identifying legitimate versus malicious applications.
Data Source
AI summary
Method, system and computer program product for detecting at least one of security threats and undesirable computer files are provided. A first method includes receiving a data stream which represents outbound, application layer messages from a first computer process to at least one second computer process. The computer processes are implemented on one or more computers. The method further includes monitoring the data stream to detect a security threat based on a whitelist having entries which contain metadata. The whitelist describes legitimate application layer messages based on a set of heuristics. The method still further includes generating a signal if a security threat is detected. A second method includes comparing a set of computer files with a whitelist which characterizes all legitimate computer files. The whitelist contains one or more entries. Each of the entries describe a plurality of legitimate computer files.


