Communication Interval Analysis for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection technologies face challenges in identifying unauthorized communications, as advanced malware can mimic regular communication patterns, making it difficult to distinguish between malicious and benign activities.

Innovation Solution

An information processing system that counts the number of communication intervals exceeding a predefined second time period within a target time period, where the interval between two communications is longer than a shorter second time period, to detect potentially unauthorized communications by outputting information on communication logs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional malware detection methods are used, then simple malware can be detected, but advanced malware with sophisticated communication patterns cannot be detected

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidability to detect advanced malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent changes the detection parameter from simple communication frequency counting to time interval analysis. By measuring the time intervals between communications and comparing them against multiple thresholds (first threshold for suspicious intervals, second threshold for normal intervals), the system can distinguish advanced malware that mimics regular communication patterns from legitimate traffic.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If communication monitoring is performed to detect malware, then unauthorized communications can be identified, but legitimate communications may be misidentified as malicious

Engineering Contradiction:
Improvedetection reliabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different detection thresholds and analysis methods to different communication patterns. By setting a first threshold for suspicious time intervals and a second threshold for normal time intervals, the system can locally adapt its detection sensitivity based on the specific communication characteristics, reducing false positives while maintaining detection reliability.

Inventive Principle:
Principle #3Local quality

3Ease of manufacture

If simple communication counting is used, then detection is easy to implement, but sophisticated malware patterns cannot be detected

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddetection precision
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent introduces dynamic threshold adjustment based on communication time intervals. Instead of using a fixed counting method, the system dynamically evaluates whether time intervals between communications exceed certain thresholds, allowing the detection mechanism to adapt to varying malware behaviors while maintaining relatively simple implementation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10783244B2Information processing system, information processing method, and program
Publication Date: 2020.09.22 LAC
  • US10783244B2 patent drawing
  • US10783244B2 patent drawing
  • US10783244B2 patent drawing

AI summary

An information processing system may be configured to count the number of one or more first time periods being included in a target time period. Each of the one or more first time periods has a plurality of communications each of which satisfies at least a condition. The plurality of communications includes two communications which are more distant from each other than a second time period which is shorter than the first time period.