Bait-Based Malware Detection via Traffic Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting information stealing software and mitigating phishing and pharming attacks are ineffective due to the sophisticated design of these threats, which allows them to evade detection and compromise sensitive information.
Innovation Solution
A system and method that employs a software agent to generate artificial sensitive information 'bait' on electronic devices, simulating user interactions to detect and analyze outgoing traffic for suspicious patterns, correlating this data with network traffic to identify and locate unwanted software, while also assessing sensitivity and risk levels to control information dissemination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If signature-based detection methods are used to identify information stealing software, then the detection process is simple and fast, but the effectiveness is limited because sophisticated malware can evade signature detection
Solution Approach 1:
The system performs preliminary actions by deploying bait data and monitoring configurations before malware can steal real information. The monitoring system is pre-configured with bait content and analysis rules, enabling proactive detection of malware attempts to exfiltrate data before actual sensitive information is compromised.
Solution Approach 2:
The patent introduces bait data as an intermediary element between the monitoring system and malware. Instead of directly detecting malware signatures, the system uses bait information as a mediator that malware will attempt to steal, allowing indirect detection of malicious activity through monitoring of bait data transmission patterns.
2Measurement precision
If comprehensive monitoring of all data transmission is implemented to detect phishing and pharming attacks, then detection accuracy improves, but system performance and processing speed deteriorate
Solution Approach 1:
The monitoring system applies local quality by focusing surveillance resources on specific high-value targets (bait data) rather than uniformly monitoring all data transmissions. The analysis rules are selectively applied to traffic patterns that match known malware behaviors, concentrating detection efforts where they are most needed while minimizing overall system overhead.
Solution Approach 2:
The system performs partial monitoring by selectively analyzing only those data transmissions that match predefined patterns of malware behavior. Instead of comprehensively examining every byte of network traffic, the system applies analysis rules to specific subsets of traffic that are more likely to contain malicious activity, achieving effective detection with reduced processing demands.
3Measurement precision
If detailed analysis rules are applied to monitor traffic patterns for malware detection, then detection precision improves, but the complexity of system configuration and maintenance increases
Solution Approach 1:
The detection system is segmented into modular components: bait deployment modules, monitoring modules with specific analysis rules, and response modules. Each analysis rule is a discrete, independently configurable unit that can be added, removed, or modified without affecting the entire system, simplifying configuration and maintenance while maintaining high detection precision.
Data Source
AI summary
A system and method for identifying infection of unwanted software on an electronic device is disclosed. A software agent configured to generate a bait and is installed on the electronic device. The bait can simulate a situation in which the user performs a login session and submits personal information or it may just contain artificial sensitive information. The output of the electronic device is monitored and analyzed for attempts of transmitting the bait. The output is analyzed by correlating the output with the bait and can be done by comparing information about the bait with the traffic over a computer network in order to decide about the existence and the location of unwanted software.


