Wireless Intrusion Prevention System for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies are ineffective in detecting and preventing new or changing malware in wireless networks, as they rely on signature-based detection methods that only address known threats and fail to stop malware from spreading before it disrupts the network.

Innovation Solution

A wireless intrusion prevention system comprising monitors, intelligent agents, and security centers that operate on both network elements and mobile devices, using heuristic rules and collaborative data analysis to detect and mitigate malicious attacks, including new or evolving malware, by scanning network traffic and device communications to identify and neutralize threats before they spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based detection methods are used to identify malware, then known malware threats can be detected, but new or changing malware cannot be detected

Engineering Contradiction:
Improvedetection accuracy for known malwareVSAvoiddetection capability for new or changing malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by deploying monitors and intelligent agents throughout the network before malware can spread. These components continuously collect behavioral data and establish baseline profiles of normal network activity, enabling the system to detect anomalies caused by new or changing malware without relying on pre-existing signatures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where security centers receive continuous data from monitors and intelligent agents, analyze behavioral patterns, and update detection rules in real-time. This feedback loop enables the system to adapt to new malware variants by learning from observed behaviors and propagating updated detection criteria throughout the network

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If network scanners are placed at firewalls to prevent malware entry, then malware at network boundaries can be blocked, but malware originating within the network cannot be detected

Engineering Contradiction:
Improveprotection from external malwareVSAvoiddetection capability for internal malware sources
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system segments the network into multiple monitoring zones with distributed monitors and intelligent agents deployed at various network elements including routers, switches, and end devices. This segmentation enables comprehensive coverage of both boundary and internal network activities, allowing detection of malware regardless of its origin point

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Intelligent agents act as intermediaries between network elements and security centers, collecting behavioral data from local devices and transmitting it to security centers for analysis. These intermediaries enable deep inspection of internal network communications without disrupting normal network operations

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of repair

If post-infection cleaning is performed on individual computers, then known malware can be removed from infected devices, but the infection cannot be prevented and new malware cannot be detected

Engineering Contradiction:
Improvemalware removal from infected devicesVSAvoidprevention capability and detection of new malware
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The system performs preliminary detection and prevention actions before infections occur by continuously monitoring network traffic and device behaviors. Intelligent agents detect suspicious activities and alert security centers to block malware propagation before devices become infected, eliminating the need for post-infection cleaning

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing devices to automatically report their behavioral data to intelligent agents and receive real-time security updates. Devices can self-identify anomalies in their own behavior and receive automated responses from the security system without requiring manual intervention

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If distributed monitors and intelligent agents are deployed throughout the network, then comprehensive malware detection is achieved, but system complexity increases

Engineering Contradiction:
Improvecomprehensive malware detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments complex security functions into modular components distributed across the network. Monitors, intelligent agents, and security centers each perform specific specialized functions, reducing the complexity burden on individual elements while achieving comprehensive detection capability through their coordinated operation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Intelligent agents serve as intermediaries that simplify the architecture by consolidating data collection from multiple sources and presenting processed information to security centers. This intermediary layer reduces communication overhead and simplifies the interaction between distributed monitors and central analysis systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8087085B2Wireless intrusion prevention system and method
Publication Date: 2011.12.27 PULSE SECURE LLC
  • US8087085B2 patent drawing
  • US8087085B2 patent drawing
  • US8087085B2 patent drawing

AI summary

A wireless intrusion prevention system and method to prevent, detect, and stop malware attacks is presented. The wireless intrusion prevention system monitors network communications for events characteristic of a malware attack, correlates a plurality of events to detect a malware attack, and performs mitigating actions to stop the malware attack.