Botnet Detection via Spam Template Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for combating botnets are inadequate, particularly in identifying and detecting secondary features of bot infections, especially when botnets comprise computers outside the control of the entity trying to eradicate them.

Innovation Solution

The method involves collecting spam message samples, forming clusters of related messages by identifying those generated using the same image or text template, using lossy compression algorithms to compare images and grouping similar messages, and determining the source of these messages to detect coordinated botnet attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional botnet detection methods are used, then detection capability is limited, but system complexity and resource consumption increase without sufficient effectiveness

Engineering Contradiction:
Improvebotnet detection effectivenessVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and analyzes specific secondary features of bot infections (spam messages, propagation patterns, attack behaviors) separately from the entire botnet system. By focusing on detectable secondary features rather than attempting to detect the complete botnet infrastructure, the system achieves effective detection with reduced complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the detection parameters from attempting to identify botnet command-and-control traffic directly to analyzing secondary features such as spam message characteristics, propagation patterns, and attack behaviors. This parameter transformation enables detection of botnets outside controlled environments

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If botnets comprise computers outside control, then direct detection of command and control traffic becomes infeasible, but secondary feature detection is required

Engineering Contradiction:
Improvedetection applicability to external botnetsVSAvoiddifficulty of detecting secondary features
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

Instead of attempting to detect botnet command-and-control traffic directly (the traditional approach), the patent inverts the detection strategy by analyzing secondary features produced by botnets (spam messages, propagation patterns, attacks). This inversion enables detection of botnets outside controlled environments where direct C&C traffic monitoring is infeasible

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent uses secondary features (spam messages, propagation patterns, attack behaviors) as intermediary indicators to detect botnet activity. These intermediaries provide observable evidence of botnet presence without requiring direct access to botnet infrastructure or C&C communications

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8612523B1Methods and apparatus for detecting botnet attacks
Publication Date: 2013.12.17 TREND MICRO INC
  • US8612523B1 patent drawing
  • US8612523B1 patent drawing
  • US8612523B1 patent drawing

AI summary

Botnet attacks may be detected by collecting samples of spam messages, forming clusters of related spam messages, and identifying the source or sources of the related spam messages. The related spam messages may be identified as those generated using the same template. For example, spam messages generated using the same image template, text template, or both may be deemed as related. To find related spam messages, images of spam messages may be extracted and compressed using a lossy compression algorithm. The compressed images may then be compared to one another to identify those generated using the same image template. The lossy compression algorithm may involve dividing an image into several blocks and then computing a value for each block for comparison.