Command and Control Channel Detection via Session Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection methods struggle to identify advanced persistent attacks through command and control channels, particularly those using new methods or encrypted traffic, as they rely on signature-based detection and fail to detect periodic access patterns.

Innovation Solution

A device and method that analyze session log information between internal and external networks to generate test data distributions for access periods, durations, and data sizes, identifying abnormal patterns as potential command and control channels, allowing for the detection of malicious activity without relying on known signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based detection methods are used, then detection of known malicious behavior is improved, but detection of new and evolving attacks deteriorates

Engineering Contradiction:
Improvedetection accuracy for known attacksVSAvoiddetection capability for new attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent changes the detection parameters from static signature matching to dynamic statistical analysis of session characteristics. It analyzes multiple parameters including session duration, data transmission volume, access frequency, and temporal patterns to detect anomalies that deviate from normal behavior distributions, enabling detection of both known and novel attacks without relying on predefined signatures

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements dynamic detection by continuously analyzing session log data and comparing actual session characteristics against statistically derived normal distributions. The detection mechanism adapts to new attack patterns by identifying deviations from established behavioral baselines, allowing the system to evolve its detection capabilities without requiring manual signature updates

Inventive Principle:
Principle #15Dynamics

2Reliability

If traditional intrusion detection devices are deployed, then protection against known threats is improved, but detection of command and control channels using new methods deteriorates

Engineering Contradiction:
Improveprotection level against known threatsVSAvoiddetection difficulty of new C2 channels
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent transitions detection from a single-dimension signature match to multi-dimensional analysis of session characteristics. It simultaneously evaluates multiple dimensions including temporal patterns (access frequency, session timing), quantitative metrics (data volume, session duration), and behavioral distributions to detect C2 channels that operate in previously undetected ways

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system introduces statistical distribution analysis as an intermediary layer between raw session logs and detection decisions. By comparing actual session characteristics against statistically derived normal distributions, the system identifies anomalies that indicate C2 communication without requiring direct knowledge of specific attack signatures or malicious IP addresses

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10218725B2Device and method for detecting command and control channel
Publication Date: 2019.02.26 NARU SECURITY
  • US10218725B2 patent drawing
  • US10218725B2 patent drawing
  • US10218725B2 patent drawing

AI summary

A device for detecting a command and control channel includes: a session log collector for collecting log information of sessions generated between at least one communication device of the first network and at least one communication device of the second network; an analyzer for generating test data for respective sessions based on the log information, and calculating a test data distribution based on test data of the sessions; and a determiner for extracting a test data value corresponding to an abnormal distribution from the test data distribution based on an abnormal distribution determination standard, and estimating sessions relating to the extracted test data value as a command and control channel.