Correlation Fractal Dimension for Malicious Software Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malicious software detection methods are inadequate in identifying encrypted network traffic, as they rely on deep packet inspection which is inefficient and ineffective for high entropy flows, and existing techniques struggle to distinguish between malicious and non-malicious encrypted traffic.

Innovation Solution

A computer-implemented method that evaluates a correlation fractal dimension (CFD) for network traffic to identify malicious software, comparing the measured CFD with a reference CFD to determine if a software component is involved in malicious network communication, allowing for the detection of both unencrypted and encrypted malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is used to detect malicious network traffic, then detection capability is improved, but processing efficiency deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the essential characteristics needed for malware detection from network traffic, specifically the fractal dimension of traffic patterns, rather than inspecting entire packet contents. This selective extraction maintains detection accuracy while dramatically reducing processing overhead compared to full deep packet inspection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The detection approach segments the analysis by focusing on specific temporal patterns and fractal characteristics of network traffic flows, dividing the complex inspection task into manageable analytical components that can be processed efficiently without examining every packet in detail.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If correlation fractal dimension analysis is applied to network traffic, then detection accuracy for encrypted traffic is improved, but computational complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms the detection problem by changing the analytical parameter from examining packet content semantics to measuring the fractal dimension of traffic timing patterns. This parameter transformation enables detection of encrypted malicious traffic through mathematical properties of temporal distribution, avoiding the need to decrypt or deeply analyze complex packet contents.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If traditional signature-based detection is used, then known malware detection is improved, but adaptability to new malware deteriorates

Engineering Contradiction:
Improveknown malware detectionVSAvoiddetect new malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent shifts from signature-based detection (comparing against known patterns) to fractal dimension analysis (measuring mathematical properties of traffic patterns). This parameter change enables the system to detect both known and unknown malware by identifying anomalous temporal patterns that deviate from normal traffic, providing inherent adaptability to new threats without requiring updated signatures.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11201876B2Malicious software identification
Publication Date: 2021.12.14 BRITISH TELECOM PLC
  • US11201876B2 patent drawing
  • US11201876B2 patent drawing
  • US11201876B2 patent drawing

AI summary

A computer implemented method to identify malicious software in a computer system includes receiving an indication of a detection of malicious network traffic communicated via a computer network accessed by the computer system; identifying a software component involved in the malicious network traffic at the computer system; evaluating a measure of a correlation fractal dimension (CFD) for at least a portion of the software component; and storing the measure of CFD for subsequent comparison with a second measure of CFD for a corresponding portion of a second software component in the computer system to identify the second software component as a software component involved in malicious network communication.