Network Defense System for Botnet Detection and Geolocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks are vulnerable to stealthy and distributed botnet attacks, which are difficult to detect due to their covert nature, posing a significant threat to cybersecurity and causing economic damage and disrupting critical Internet-connected systems.

Innovation Solution

A network defense system that includes a sensor infrastructure for collecting and analyzing network traffic data, applying advanced algorithms to detect malicious patterns, and visualizing threats on a geolocated map, allowing for rapid deployment of new algorithms to counter evolving botnet threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If advanced algorithms are applied to detect stealth botnets, then detection precision is improved, but device complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the detection task into multiple components: network sensors collect raw data, a data collection and storage subsystem aggregates information, computing clusters execute specialized algorithms, and a visualization subsystem presents results. This segmentation allows advanced algorithms to be applied without overwhelming a single system component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including a data collection and storage subsystem that bridges sensors and algorithms, and a visualization subsystem that mediates between algorithm outputs and users. These intermediaries manage complexity by handling data transformation and presentation tasks separately from the core detection algorithms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If large volumes of data are collected from distributed sensors, then detection reliability is improved, but loss of time in data transmission and processing increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoiddata transmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-positioning network sensors throughout the network infrastructure and pre-configuring the data collection and storage subsystem. Sensors continuously collect and buffer data before analysis is required, so when detection is needed, the data is already available locally rather than needing to be transmitted from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transitions from centralized data collection to a distributed architecture where sensors and storage nodes are distributed across multiple geographic locations. This spatial dimensionality change allows data to be processed closer to its source, reducing transmission distances and time while maintaining data volume for reliable detection.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If specialized algorithms are deployed for each botnet type, then detection precision is improved, but adaptability decreases

Engineering Contradiction:
Improvedetection precisionVSAvoidadaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The computing cluster is designed as a universal platform capable of executing multiple different detection algorithms. The system can load and run specialized algorithms for different botnet types through a common interface, allowing one system to perform multiple detection functions without requiring separate specialized systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages adaptability through parameter changes in algorithm configuration rather than structural changes. Different detection algorithms can be selected and configured by adjusting parameters such as detection thresholds, data sources, and analysis methods, allowing the same infrastructure to adapt to different botnet threats without redesign.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If computationally intensive algorithms are executed, then detection precision is improved, but use of energy increases

Engineering Contradiction:
Improvedetection precisionVSAvoidenergy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system segments computationally intensive tasks across a cluster of computing nodes rather than concentrating all processing in one location. This distribution allows energy consumption to be spread across multiple devices, and enables selective activation of only the computational resources needed for each specific detection task.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9083741B2Network defense system and framework for detecting and geolocating botnet cyber attacks
Publication Date: 2015.07.14 ARCHITECTURE TECH CORP
  • US9083741B2 patent drawing
  • US9083741B2 patent drawing
  • US9083741B2 patent drawing

AI summary

A network defense system is described that provides network sensor infrastructure and a framework for managing and executing advanced cyber security algorithms specialized for detecting highly-distributed, stealth network attacks. In one example, a system includes a data collection and storage subsystem that provides a central repository to store network traffic data received from sensors positioned within geographically separate networks. Cyber defense algorithms analyze the network traffic data and detect centrally-controlled malware that is configured to perform distributed network attacks (“botnet attacks”) from devices within the geographically separate networks. A visualization and decision-making subsystem generates a user interface that presents an electronic map of geographic locations of source devices and target devices of the botnet attacks. The data collection and storage subsystem stores a manifest of parameters for the network traffic data to be analyzed by each of the cyber defense algorithms.