Client Malware IP Reporting for Botnet Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting botnet nodes are complex and resource-intensive, requiring extensive network traffic monitoring by ISPs, which is costly and inefficient.
Innovation Solution
A method that crowdsources suspect IP addresses from client computers with detected malware, where locally installed antivirus software monitors connections, sends lists to a central server for filtering and database updates, and uses prevalence factors to identify and block malicious IP addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network traffic monitoring is performed by ISPs to detect botnet nodes, then detection capability is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent enables client computers to autonomously detect malware and collect suspicious IP addresses themselves, rather than relying on centralized ISP monitoring. Each infected computer becomes a self-serving detection node that automatically reports findings to the security software provider, distributing the detection workload across the network.
Solution Approach 2:
The patent extracts the detection function from the centralized ISP network infrastructure and relocates it to individual client computers. By taking out the monitoring capability from the network core and placing it at the edge devices, the system reduces centralized complexity while maintaining detection effectiveness.
2Reliability
If network traffic monitoring is performed by ISPs to detect botnet nodes, then detection capability is improved, but resource consumption and cost increase
Solution Approach 1:
The patent enables client computers to autonomously detect malware and collect suspicious IP addresses themselves, rather than relying on centralized ISP monitoring. Each infected computer becomes a self-serving detection node that automatically reports findings to the security software provider, distributing the detection workload across the network.
Solution Approach 2:
The patent extracts the detection function from the centralized ISP network infrastructure and relocates it to individual client computers. By taking out the monitoring capability from the network core and placing it at the edge devices, the system reduces centralized complexity while maintaining detection effectiveness.
3Reliability
If all compromised IP addresses within a botnet are known, then protection reliability is improved, but the difficulty of discovery increases
Solution Approach 1:
The patent enables client computers to autonomously detect malware and collect suspicious IP addresses themselves, rather than relying on centralized ISP monitoring. Each infected computer becomes a self-serving detection node that automatically reports findings to the security software provider, distributing the detection workload across the network.
Solution Approach 2:
The patent merges the detection efforts of multiple client computers into a centralized database at the security software provider. By combining IP address lists from numerous infected machines, the system accumulates a comprehensive blacklist that improves protection reliability for all users collectively.
Data Source
AI summary
A method of discovering suspect IP addresses, the method including, at a client computer: monitoring the computer for malware; on detection of malware, obtaining a list of IP addresses with which a connection has been made or attempted at the client computer within a preceding time frame; sending the list of IP addresses to a central server; and receiving from the central server a blacklist of suspect IP addresses to allow the client computer to block connections with IP addresses within said blacklist.


