Botnet Detection via Spam Template Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for combating botnets are inadequate, particularly in identifying and detecting secondary features of bot infections, especially when botnets comprise computers outside the control of the entity trying to eradicate them.
Innovation Solution
The method involves collecting spam message samples, forming clusters of related messages by identifying those generated using the same image or text template, using lossy compression algorithms to compare images and grouping similar messages, and determining the source of these messages to detect coordinated botnet attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional botnet detection methods are used, then detection capability is limited, but system complexity and resource consumption increase without sufficient effectiveness
Solution Approach 1:
The patent extracts and analyzes specific secondary features of bot infections (spam messages, propagation patterns, attack behaviors) separately from the entire botnet system. By focusing on detectable secondary features rather than attempting to detect the complete botnet infrastructure, the system achieves effective detection with reduced complexity
Solution Approach 2:
The patent changes the detection parameters from attempting to identify botnet command-and-control traffic directly to analyzing secondary features such as spam message characteristics, propagation patterns, and attack behaviors. This parameter transformation enables detection of botnets outside controlled environments
2Adaptability or versatility
If botnets comprise computers outside control, then direct detection of command and control traffic becomes infeasible, but secondary feature detection is required
Solution Approach 1:
Instead of attempting to detect botnet command-and-control traffic directly (the traditional approach), the patent inverts the detection strategy by analyzing secondary features produced by botnets (spam messages, propagation patterns, attacks). This inversion enables detection of botnets outside controlled environments where direct C&C traffic monitoring is infeasible
Solution Approach 2:
The patent uses secondary features (spam messages, propagation patterns, attack behaviors) as intermediary indicators to detect botnet activity. These intermediaries provide observable evidence of botnet presence without requiring direct access to botnet infrastructure or C&C communications
Data Source
AI summary
Botnet attacks may be detected by collecting samples of spam messages, forming clusters of related spam messages, and identifying the source or sources of the related spam messages. The related spam messages may be identified as those generated using the same template. For example, spam messages generated using the same image template, text template, or both may be deemed as related. To find related spam messages, images of spam messages may be extracted and compressed using a lossy compression algorithm. The compressed images may then be compared to one another to identify those generated using the same image template. The lossy compression algorithm may involve dividing an image into several blocks and then computing a value for each block for comparison.


