Wireless Interference Pattern Action Detection for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web security gateways face challenges in detecting and preventing malicious activities on unmanaged endpoint devices within private networks, particularly due to SSL encryption which hinders the decryption and inspection of network traffic, and existing solutions struggle to identify risky user behaviors across multiple connections or within web pages.
Innovation Solution
A system that collects time-series data on interference patterns in wireless transmissions between endpoint devices and a web security gateway, using machine-learning models to infer user actions and enforce network security policies without requiring agents on endpoint devices, by training models on reported user activities and interference patterns to block suspicious communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SSL encryption is used to protect network communications, then data privacy and integrity are improved, but the ability to decrypt and inspect network traffic deteriorates
Solution Approach 1:
The patent introduces wireless transmission interference patterns as an intermediary indicator that mediates between SSL encryption and security inspection needs. Instead of directly decrypting encrypted traffic, the system uses interference patterns caused by user actions (detected through wireless transmissions) as a proxy to infer user behavior and identify malicious activities, thus resolving the contradiction between maintaining SSL encryption and enabling traffic inspection
Solution Approach 2:
The patent replaces the traditional mechanical approach of decrypting SSL traffic to inspect content with a different detection mechanism based on wireless transmission interference patterns. By substituting the inspection method from content analysis to interference pattern analysis, the system can identify malicious activities without compromising SSL encryption
2Reliability
If web security gateways monitor traffic to detect malicious activities, then network security is improved, but the complexity of the security system deteriorates
Solution Approach 1:
The patent extracts the complexity of behavior analysis from the web security gateway by using interference patterns as simplified indicators. Instead of analyzing complex encrypted traffic content, the system extracts wireless transmission interference patterns that directly reflect user actions, thereby reducing the complexity of the security system while maintaining effective malicious activity detection
Solution Approach 2:
The patent changes the detection parameter from encrypted traffic content to wireless transmission interference patterns. This parameter change simplifies the security system architecture by using physically measurable interference patterns (signal strength variations, transmission timing) instead of complex content decryption and analysis mechanisms
3Measurement precision
If agents are installed on endpoint devices to monitor user actions, then detection accuracy is improved, but device complexity and deployment difficulty deteriorate
Solution Approach 1:
The patent uses wireless transmission interference patterns as an intermediary that carries information about user actions without requiring agents on endpoint devices. The interference patterns serve as a mediator that enables accurate user action detection through existing wireless infrastructure, eliminating the need for additional software agents while maintaining detection precision
Solution Approach 2:
The patent enables the wireless network infrastructure to serve the dual purpose of both communication and security monitoring. The existing wireless transmissions automatically generate interference patterns that reveal user actions, allowing the system to monitor endpoint devices without installing additional agents or software, thus reducing device complexity while maintaining detection accuracy
Data Source
AI summary
Systems of the present disclosure can detect user activities on endpoint devices based on the interference patterns those actions produce in wireless transmissions between those endpoint devices and another device (e.g., an edge device operating as a web security gateway). A web security gateway sends time-series data describing interference on wireless transmissions sent from, or received by, an agentless endpoint device to a network security service. In response, the network security service uses a machine-learning model to infer a type of an action that occurred on the agentless endpoint device concurrently with the wireless transmissions. The network security service sends an indication of the action type to the web security gateway. The web security gateway applies a network security policy to the action or a network communication associated therewith.


