Autonomous System Detection via Traffic and Web Search Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face challenges in detecting and differentiating between rentable and non-rentable autonomous systems (ASNs), particularly in identifying bulletproof hosting services that may be used for malicious activities, as existing methods lack effectiveness in distinguishing between benign and malicious traffic patterns.

Innovation Solution

A method and system that collect data transmissions from multiple endpoints to multiple Internet sites, generate an ASN data traffic model, perform web searches using indicative keywords, and predict suspicious ASNs based on their modeled data transmissions and relationships, utilizing a combination of data traffic and web search models to identify rentable and bulletproof ASNs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional intrusion detection systems are used to monitor network traffic, then basic security threats can be detected, but they cannot effectively differentiate between benign and malicious traffic patterns from autonomous systems

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the detection process into multiple independent modules: traffic data collection from multiple endpoints, ASN identification, web search analysis with indicative keywords, and scoring/prediction. Each module handles a specific aspect of the detection task, allowing for specialized processing and improving overall detection accuracy without creating a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary web search component that acts as a mediator between raw traffic data and final malicious ASN identification. The web search engine queries using indicative keywords to gather additional contextual information about the autonomous systems, bridging the gap between basic traffic monitoring and sophisticated threat detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive data collection from multiple endpoints is performed to improve detection accuracy, then the volume of data to be processed increases significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the most relevant features from the collected traffic data, such as ASN identifiers, domain information, and traffic patterns associated with indicative keywords. Rather than processing all raw data, the extraction focuses on key elements that are most predictive of malicious activity, reducing the effective data volume while maintaining detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial action by collecting data from multiple endpoints but processing it through selective filtering and sampling. The system performs web searches only for ASNs that meet certain criteria (e.g., those with suspicious traffic patterns), rather than querying all possible ASNs, thus reducing the overall computational burden while maintaining effective detection coverage.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If web searches with multiple indicative keywords are performed for each ASN to improve prediction accuracy, then the computational time and resources required increase

Engineering Contradiction:
Improveprediction accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary filtering of ASNs based on traffic pattern analysis before conducting web searches. ASNs that exhibit suspicious characteristics in the initial traffic analysis are prioritized for web search investigation, while clearly benign ASNs are excluded. This preliminary action reduces the number of web searches required, saving time and computational resources.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically adjusts the number and type of indicative keywords used in web searches based on the risk level and context of each ASN. For high-risk ASNs, more comprehensive keyword sets are used, while for lower-risk cases, fewer targeted keywords suffice. This parameter adjustment optimizes the balance between prediction accuracy and processing time.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10425436B2Identifying bulletproof autonomous systems
Publication Date: 2019.09.24 PALO ALTO NETWORKS INC
  • US10425436B2 patent drawing
  • US10425436B2 patent drawing
  • US10425436B2 patent drawing

AI summary

A method, including collecting data transmitted from endpoints to Internet sites having respective domains and respective IP addresses, and transmissions to IP addresses of ASN numbers or ASN names included in a list of ASNs. An ASN data traffic model is generated by modeling, for each given ASN, data transmitted to any of the IP address of the given ASN based on the data, and for each given ASN and a set of keywords, multiple web searches are performed, each of the web searches including a given keyword and an ASN name or a number for the given ASN. Based on the web searches, a model of relationships between the keywords and the ASNs is generated, and one or more of the ASNs are predicted to be suspicious based on their respective modeled data transmissions and their respective modeled relationships between the keywords and the one or more ASNs.