Botnet Detection via Traffic Analysis Device Query

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods fail to support real-time monitoring and topology generation of Botnets, which are critical for effective detection and mitigation of network attacks.

Innovation Solution

A method and system that involves obtaining address information of a control host using an auto breakout environment, sending query requests to a traffic analysis device, and receiving response messages to identify connected Bot hosts, enabling real-time detection and topology construction of Botnets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional detection methods (honeypot, reverse engineering, offline analysis) are used to obtain Botnet information, then detection accuracy can be improved, but real-time monitoring capability deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidreal-time monitoring capability
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing traffic analysis devices and query mechanisms in advance. When a Bot sample is detected, the system can immediately query the traffic analysis device for connected Bot hosts without waiting for manual analysis or offline processing, enabling real-time response while maintaining accurate detection through pre-configured analysis capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a traffic analysis device as an intermediary between Bot sample detection and Botnet topology construction. This intermediary automatically analyzes traffic data and provides connected host information, eliminating the need for manual reverse engineering while enabling real-time queries. The intermediary bridges the gap between accurate detection requirements and real-time monitoring needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual analysis methods are used to construct Botnet topology, then detection precision can be improved, but system complexity and operational difficulty increase

Engineering Contradiction:
Improvetopology detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically constructing Botnet topology through programmed interactions between the detection apparatus and traffic analysis device. The apparatus automatically queries for control host address information, receives response messages with Bot host addresses, and constructs topology without manual intervention. This automation maintains high detection precision while significantly reducing system complexity and operational burden.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The traffic analysis device serves multiple functions: it analyzes traffic data, identifies connected Bot hosts, provides address information, and supports topology construction. This multi-functional approach consolidates what would otherwise require separate manual analysis tools and processes, reducing overall system complexity while maintaining comprehensive detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive Botnet analysis is performed using conventional methods, then detection reliability can be improved, but productivity and response speed decrease

Engineering Contradiction:
Improvedetection reliabilityVSAvoidresponse speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system maintains continuous useful action by establishing persistent traffic analysis capabilities and automated query mechanisms. Once a Bot sample is detected, the system continuously queries the traffic analysis device for connected hosts and automatically updates the Botnet topology. This continuous automated process maintains high detection reliability while dramatically improving response speed and productivity compared to intermittent manual analysis.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8904532B2Method, apparatus and system for detecting botnet
Publication Date: 2014.12.02 HUAWEI TECH CO LTD
  • US8904532B2 patent drawing
  • US8904532B2 patent drawing
  • US8904532B2 patent drawing

AI summary

A method, an apparatus, and a system for detecting Botnet are disclosed. The method for detecting Botnet includes: obtaining an address information about a control host in a Bot sample by using an auto breakout environment; sending a query request message to a traffic analysis device to obtain an address information of a Bot host connected with the control host, in which the query request message carries the address information about the control host; and receiving a query response message returned by the traffic analysis device, in which the query response message carries the address information of the Bot host connected with the control host. The method for detecting Botnet can obtain the Botnet information in real time and construct a topology of the Botnet.