Worm Containment via Dynamic Data Flow Analysis and Self-Certifying Alerts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Worms pose a significant threat to networked computers by exploiting vulnerabilities in software, leading to rapid spread and difficulty in detection and containment, as existing technologies lack efficient methods for automated detection and alert dissemination across mutually untrusting systems.

Innovation Solution

A worm containment system that employs dynamic data flow analysis for detection, generates self-certifying alerts to verify software vulnerabilities, and utilizes a resilient protocol for timely alert propagation across a peer-to-peer network, enabling collaboration among untrusting computers to contain worm outbreaks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If dynamic data flow analysis is used for worm detection, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The worm containment system is divided into multiple independent modules including detection modules that perform dynamic data flow analysis, alert generation modules, and propagation modules. Each module handles specific tasks independently, allowing complex detection operations to be broken down into manageable segments that can be executed efficiently without overwhelming the system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces alert messages as intermediary carriers that transmit vulnerability information between nodes. These alerts serve as mediators that encapsulate detection results and propagate them through the network, reducing the direct complexity of inter-node communication while maintaining high detection accuracy through structured information exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If alerts are propagated rapidly across the network, then response time is improved, but network traffic increases

Engineering Contradiction:
Improveresponse timeVSAvoidnetwork traffic
Core Design Contradiction:
Loss of timeVSQuantity of substance

Solution Approach 1:

The system performs preliminary filtering and validation of alert messages before propagation. Nodes pre-process incoming alerts to verify their authenticity and relevance, eliminating redundant transmissions. This preliminary action reduces the volume of traffic that needs to be propagated across the network while maintaining rapid response times for genuine threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements location-aware propagation where alert messages are routed and distributed based on local network conditions and node characteristics. Different regions of the network receive alerts at different times and through different paths, optimizing the balance between rapid dissemination and traffic management by adapting to local qualities of each network segment.

Inventive Principle:
Principle #3Local quality

3Reliability

If self-certifying alerts are implemented, then alert authenticity is improved, but computational overhead increases

Engineering Contradiction:
Improvealert authenticityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The self-certifying alert mechanism implements partial verification where nodes perform selective validation of alert signatures and cryptographic proofs rather than complete re-verification of all alert contents. This partial action approach maintains high alert authenticity by verifying critical security elements while reducing the excessive computational overhead of full verification processes.

Inventive Principle:
Principle #16Partial or excessive action

4Productivity

If the containment system operates autonomously, then productivity is improved, but difficulty of operation increases

Engineering Contradiction:
Improveautomated response efficiencyVSAvoidsystem configuration complexity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The worm containment system is designed to be self-configuring and self-managing. Nodes automatically discover their roles, establish connections with other nodes, and adjust their detection and propagation parameters based on local conditions and received alerts. This self-service capability enables autonomous operation and high productivity while reducing the need for manual configuration and operation intervention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7603715B2Containment of worms
Publication Date: 2009.10.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7603715B2 patent drawing
  • US7603715B2 patent drawing
  • US7603715B2 patent drawing

AI summary

One aspect of the invention is a vulnerability detection mechanism that can detect a large class of attacks through dynamic dataflow analysis. Another aspect of the invention includes self-certifying alerts as the basis for safely sharing knowledge about worms. Another aspect of the invention is a resilient and self-organizing protocol to propagate alerts to all non-infected nodes in a timely fashion, even when under active attack during a worm outbreak. Another aspect of the invention is a system architecture that enables a large number of mutually untrusting computers to collaborate in the task of stopping a previously unknown worm, even when the worm is spreading rapidly and exploiting unknown vulnerabilities in popular software packages.