Autonomous System Detection via Traffic and Web Search Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems face challenges in detecting and differentiating between rentable and non-rentable autonomous systems (ASNs), particularly in identifying bulletproof hosting services that may be used for malicious activities, as existing methods lack effectiveness in distinguishing between benign and malicious traffic patterns.
Innovation Solution
A method and system that collect data transmissions from multiple endpoints to multiple Internet sites, generate an ASN data traffic model, perform web searches using indicative keywords, and predict suspicious ASNs based on their modeled data transmissions and relationships, utilizing a combination of data traffic and web search models to identify rentable and bulletproof ASNs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional intrusion detection systems are used to monitor network traffic, then basic security threats can be detected, but they cannot effectively differentiate between benign and malicious traffic patterns from autonomous systems
Solution Approach 1:
The system segments the detection process into multiple independent modules: traffic data collection from multiple endpoints, ASN identification, web search analysis with indicative keywords, and scoring/prediction. Each module handles a specific aspect of the detection task, allowing for specialized processing and improving overall detection accuracy without creating a monolithic complex system.
Solution Approach 2:
The patent introduces an intermediary web search component that acts as a mediator between raw traffic data and final malicious ASN identification. The web search engine queries using indicative keywords to gather additional contextual information about the autonomous systems, bridging the gap between basic traffic monitoring and sophisticated threat detection.
2Measurement precision
If comprehensive data collection from multiple endpoints is performed to improve detection accuracy, then the volume of data to be processed increases significantly
Solution Approach 1:
The system extracts only the most relevant features from the collected traffic data, such as ASN identifiers, domain information, and traffic patterns associated with indicative keywords. Rather than processing all raw data, the extraction focuses on key elements that are most predictive of malicious activity, reducing the effective data volume while maintaining detection accuracy.
Solution Approach 2:
The patent implements partial action by collecting data from multiple endpoints but processing it through selective filtering and sampling. The system performs web searches only for ASNs that meet certain criteria (e.g., those with suspicious traffic patterns), rather than querying all possible ASNs, thus reducing the overall computational burden while maintaining effective detection coverage.
3Measurement precision
If web searches with multiple indicative keywords are performed for each ASN to improve prediction accuracy, then the computational time and resources required increase
Solution Approach 1:
The system performs preliminary filtering of ASNs based on traffic pattern analysis before conducting web searches. ASNs that exhibit suspicious characteristics in the initial traffic analysis are prioritized for web search investigation, while clearly benign ASNs are excluded. This preliminary action reduces the number of web searches required, saving time and computational resources.
Solution Approach 2:
The patent dynamically adjusts the number and type of indicative keywords used in web searches based on the risk level and context of each ASN. For high-risk ASNs, more comprehensive keyword sets are used, while for lower-risk cases, fewer targeted keywords suffice. This parameter adjustment optimizes the balance between prediction accuracy and processing time.
Data Source
AI summary
A method, including collecting data transmitted from endpoints to Internet sites having respective domains and respective IP addresses, and transmissions to IP addresses of ASN numbers or ASN names included in a list of ASNs. An ASN data traffic model is generated by modeling, for each given ASN, data transmitted to any of the IP address of the given ASN based on the data, and for each given ASN and a set of keywords, multiple web searches are performed, each of the web searches including a given keyword and an ASN name or a number for the given ASN. Based on the web searches, a model of relationships between the keywords and the ASNs is generated, and one or more of the ASNs are predicted to be suspicious based on their respective modeled data transmissions and their respective modeled relationships between the keywords and the one or more ASNs.


