Wireless Interference Pattern Action Detection for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web security gateways face challenges in detecting and preventing malicious activities on unmanaged endpoint devices within private networks, particularly due to SSL encryption which hinders the decryption and inspection of network traffic, and existing solutions struggle to identify risky user behaviors across multiple connections or within web pages.

Innovation Solution

A system that collects time-series data on interference patterns in wireless transmissions between endpoint devices and a web security gateway, using machine-learning models to infer user actions and enforce network security policies without requiring agents on endpoint devices, by training models on reported user activities and interference patterns to block suspicious communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSL encryption is used to protect network communications, then data privacy and integrity are improved, but the ability to decrypt and inspect network traffic deteriorates

Engineering Contradiction:
Improvedata privacyVSAvoidtraffic inspection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces wireless transmission interference patterns as an intermediary indicator that mediates between SSL encryption and security inspection needs. Instead of directly decrypting encrypted traffic, the system uses interference patterns caused by user actions (detected through wireless transmissions) as a proxy to infer user behavior and identify malicious activities, thus resolving the contradiction between maintaining SSL encryption and enabling traffic inspection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of decrypting SSL traffic to inspect content with a different detection mechanism based on wireless transmission interference patterns. By substituting the inspection method from content analysis to interference pattern analysis, the system can identify malicious activities without compromising SSL encryption

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If web security gateways monitor traffic to detect malicious activities, then network security is improved, but the complexity of the security system deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complexity of behavior analysis from the web security gateway by using interference patterns as simplified indicators. Instead of analyzing complex encrypted traffic content, the system extracts wireless transmission interference patterns that directly reflect user actions, thereby reducing the complexity of the security system while maintaining effective malicious activity detection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the detection parameter from encrypted traffic content to wireless transmission interference patterns. This parameter change simplifies the security system architecture by using physically measurable interference patterns (signal strength variations, transmission timing) instead of complex content decryption and analysis mechanisms

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If agents are installed on endpoint devices to monitor user actions, then detection accuracy is improved, but device complexity and deployment difficulty deteriorate

Engineering Contradiction:
Improveuser action detection accuracyVSAvoidendpoint device complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent uses wireless transmission interference patterns as an intermediary that carries information about user actions without requiring agents on endpoint devices. The interference patterns serve as a mediator that enables accurate user action detection through existing wireless infrastructure, eliminating the need for additional software agents while maintaining detection precision

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables the wireless network infrastructure to serve the dual purpose of both communication and security monitoring. The existing wireless transmissions automatically generate interference patterns that reveal user actions, allowing the system to monitor endpoint devices without installing additional agents or software, thus reducing device complexity while maintaining detection accuracy

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10924513B1Action detection and network security policy enforcement based on wireless-transmission interference patterns
Publication Date: 2021.02.16 GEN DIGITAL INC
  • US10924513B1 patent drawing
  • US10924513B1 patent drawing
  • US10924513B1 patent drawing

AI summary

Systems of the present disclosure can detect user activities on endpoint devices based on the interference patterns those actions produce in wireless transmissions between those endpoint devices and another device (e.g., an edge device operating as a web security gateway). A web security gateway sends time-series data describing interference on wireless transmissions sent from, or received by, an agentless endpoint device to a network security service. In response, the network security service uses a machine-learning model to infer a type of an action that occurred on the agentless endpoint device concurrently with the wireless transmissions. The network security service sends an indication of the action type to the web security gateway. The web security gateway applies a network security policy to the action or a network communication associated therewith.