Whitelist Network Traffic Detection for Insider Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems struggle to detect and prevent insider leaks and encrypted or obfuscated data leaks due to their reliance on blacklists and inability to differentiate between human and automated network traffic, leading to high false-positive rates and failure to identify non-browser web applications.

Innovation Solution

A method and system that utilize a whitelist-based approach to detect security threats and undesirable computer files by analyzing network traffic for timing and formatting anomalies, generating alerts for irregular patterns, and associating these with specific applications, while also measuring unconstrained outbound bandwidth to identify potential information leaks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security systems use blacklists to detect threats, then they can identify known malicious patterns, but they produce high false-positive rates and cannot detect encrypted or obfuscated data leaks

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfalse-positive rate
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent inverts the conventional blacklist approach by implementing a whitelist-based system that defines legitimate traffic patterns. Instead of trying to identify and block all known threats, the system establishes what normal traffic should look like and flags deviations from these patterns. This inversion allows the system to detect previously undetectable threats including encrypted data leaks while significantly reducing false positives, as the whitelist provides a reliable baseline for legitimate activity.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent changes the detection parameters from static signature matching to dynamic behavioral analysis. By monitoring timing patterns, message formatting, frequency of communication, and other temporal parameters, the system can identify anomalous behavior that indicates potential threats. This parameter change enables detection of encrypted and obfuscated traffic by focusing on behavioral characteristics rather than content analysis, thereby improving reliability without increasing false positives.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security systems monitor all network traffic for threats, then they can detect potential security incidents, but they cannot differentiate between human and automated traffic leading to high false positives

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidtraffic pattern differentiation
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces temporal parameters as key differentiation factors between human and automated traffic. By analyzing timing patterns such as inter-message intervals, communication frequency, and rhythmic regularity, the system can distinguish human-operated applications from automated bots. Human traffic exhibits more variable and less predictable timing patterns, while automated traffic shows more regular, programmed intervals. This parameter-based differentiation significantly improves measurement precision in threat detection.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback mechanisms that continuously learn from observed traffic patterns. By monitoring and adapting to the behavioral characteristics of legitimate applications over time, the system refines its understanding of what constitutes normal human versus automated traffic. This feedback loop enables the system to improve its differentiation capabilities dynamically, reducing false positives while maintaining reliable threat detection.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If conventional systems rely on blacklists, then they can block known malicious files, but they fail to identify non-browser web applications and encrypted data leaks

Engineering Contradiction:
Improvemalicious file blockingVSAvoiddetection of unknown threats
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent inverts the detection approach by using whitelists to define legitimate web application behavior rather than blacklists to block known malware. By establishing baseline patterns for legitimate web traffic including timing, formatting, and communication protocols, the system can identify deviations that indicate non-browser applications or encrypted data leaks. This inversion provides adaptability to detect unknown threats while maintaining the ability to block known malicious files through pattern deviation detection.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent creates a universal detection framework that can identify multiple types of threats using the same behavioral analysis mechanisms. The system's timing and formatting analysis capabilities apply universally across different threat types including non-browser web applications, encrypted data leaks, and traditional malware. This multi-functional approach enhances adaptability by using a single versatile detection system rather than separate specialized systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If security systems analyze detailed network traffic patterns, then they can identify specific applications and threats, but they increase system complexity and processing overhead

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent focuses analysis on a selective set of temporal parameters such as timing intervals, message frequency, and formatting patterns rather than attempting to analyze all aspects of network traffic. By changing the parameters under analysis to these specific temporal characteristics, the system achieves high application identification accuracy without requiring complex analysis of every traffic attribute. This parameter selection reduces processing overhead while maintaining precision in identifying legitimate versus malicious applications.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9055093B2Method, system and computer program product for detecting at least one of security threats and undesirable computer files
Publication Date: 2015.06.09 SYROWIK DAVID R
  • US9055093B2 patent drawing
  • US9055093B2 patent drawing
  • US9055093B2 patent drawing

AI summary

Method, system and computer program product for detecting at least one of security threats and undesirable computer files are provided. A first method includes receiving a data stream which represents outbound, application layer messages from a first computer process to at least one second computer process. The computer processes are implemented on one or more computers. The method further includes monitoring the data stream to detect a security threat based on a whitelist having entries which contain metadata. The whitelist describes legitimate application layer messages based on a set of heuristics. The method still further includes generating a signal if a security threat is detected. A second method includes comparing a set of computer files with a whitelist which characterizes all legitimate computer files. The whitelist contains one or more entries. Each of the entries describe a plurality of legitimate computer files.