Automated Botnet Detection via Test Computer Environment Refresh

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and monitoring botnets are labor-intensive and require significant skilled IT personnel, making them inefficient for rapid identification and mitigation of malicious software effects across distributed computer systems.

Innovation Solution

A method and system that utilize a test computer to store and trial local components of malicious programs, running them in an execution environment, recording messages generated, and automatically refreshing the environment between trials, allowing for automated monitoring of botnet messages without extensive user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual detection and monitoring methods are used for botnets, then detection accuracy can be maintained, but significant labor and skilled IT personnel are required making the process inefficient

Engineering Contradiction:
Improvedetection efficiencyVSAvoidlabor requirement
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system enables self-service automation where the test computer automatically executes malicious program components, monitors messages, and refreshes the execution environment without human intervention. The automated workflow includes storing local components, trialling them in an execution environment, recording messages, and replacing the environment between trials, all performed autonomously to eliminate the need for skilled IT personnel while maintaining detection accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-storing multiple local components of malicious programs and preparing a clean execution environment before actual detection begins. The test computer is pre-configured with the necessary infrastructure (repository of malicious components, execution environment program, recording mechanisms) so that when detection starts, it can immediately and efficiently trial components without requiring manual setup for each detection task

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If the execution environment is not refreshed between trials, then system resources are conserved, but malicious software effects accumulate preventing accurate detection of subsequent components

Engineering Contradiction:
Improvedetection accuracyVSAvoidenvironment management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies discarding and recovering by automatically replacing the execution environment with a clean copy between each trial of a malicious program component. This ensures that effects from previous trials (such as modified system files, registered services, or persistent processes) are discarded, while the automated recovery process restores the environment to a known good state, enabling accurate detection of each subsequent component without cross-contamination

Inventive Principle:
Principle #34Discarding and recovering

Solution Approach 2:

The system uses copying by maintaining a clean copy of the execution environment program and automatically copying it to replace the used environment between trials. This ensures each trial starts with a pristine, identical environment state, eliminating the complexity of manually managing environment cleanup while guaranteeing detection accuracy by preventing accumulation of malicious software effects

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9329973B2Method and apparatus for automated testing software
Publication Date: 2016.05.03 BRITISH TELECOM PLC
  • US9329973B2 patent drawing
  • US9329973B2 patent drawing
  • US9329973B2 patent drawing

AI summary

A system for discovering, or at least providing information that might assist in discovering, compromised computers involved in a malicious distributed program. The system is based around a test computer which is deliberately infected by a component of the malicious distributed program. Traffic sent by that test computer when under control of that component is recorded. More sophisticated malicious programs alter the system files or system programs on the computer which they infect—this creates a problem in that automation of the discovery process is difficult to achieve. Embodiments described here overcome this problem by running through a list of malicious program components, and in between executing (58) each one, refreshing (52, 64) the environment (system files and system programs) in which the malicious program component runs. Such techniques could be used by network operators or groups of network operators in discovering and thereafter disabling harmful distributed programs which run on computers connected to the network they operate.