Crowdsourced Log Analysis for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection systems face challenges in analyzing comprehensive information from business units or customers and require continuous learning to discover hidden patterns of potential attackers, struggling to provide extensive coverage of various malware types and their emerging patterns.
Innovation Solution
A crowdsourcing log analysis system that aggregates and normalizes log files from multiple client networks, using a breach detection platform to generate risk factors for suspect entities and provide alerting mechanisms, leveraging third-party security products and machine learning algorithms for behavioral detection and threat intelligence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional malware detection systems are used, then detection capability is limited to individual systems, but coverage and accuracy of malware detection deteriorates due to lack of comprehensive data analysis
Solution Approach 1:
The patent combines log data from multiple third-party security products and multiple client networks into a unified analysis system. The crowdsourcing platform aggregates logs from diverse sources including antivirus software, firewalls, and intrusion detection systems, merging them into a comprehensive dataset that enhances both detection accuracy and malware type coverage through collective intelligence.
Solution Approach 2:
The system creates a universal log analysis platform that can handle various types of security logs from different vendors and products. The normalized log structure and machine learning models are designed to be vendor-agnostic, enabling the system to detect multiple malware types (viruses, worms, trojans, ransomware, etc.) using a single multi-functional platform.
2Reliability
If comprehensive log analysis from multiple sources is implemented, then malware detection capability improves, but system complexity increases due to data aggregation and normalization requirements
Solution Approach 1:
The patent introduces a crowdsourcing platform as an intermediary between third-party security products and the final detection system. This platform receives logs from multiple vendors, normalizes them into a unified format, and presents standardized data to the machine learning models, thereby simplifying the overall system architecture while maintaining high reliability through comprehensive data aggregation.
Solution Approach 2:
The system transforms log data from various formats and vendors into a standardized parameter structure through normalization. By changing the parameters of log entries into a unified schema, the system enables consistent analysis across diverse data sources without requiring complex custom processing for each vendor, thus reducing system complexity while improving reliability.
3Adaptability or versatility
If continuous learning processes are applied to discover hidden patterns, then detection of emerging malware patterns improves, but computational resources and analysis time increase
Solution Approach 1:
The system performs preliminary actions by continuously training machine learning models on aggregated log data from the crowdsourcing platform. The models learn hidden patterns and malware signatures in advance, building a knowledge base that enables rapid detection of emerging threats without requiring extensive real-time analysis, thus reducing analysis time while maintaining high adaptability.
Solution Approach 2:
The patent implements feedback mechanisms where detection results and new log data continuously feed back into the machine learning models. This creates a continuous learning loop where the system adapts to emerging malware patterns over time, improving detection capability while optimizing analysis time through learned patterns that reduce the computational burden of real-time analysis.
Data Source
AI summary
A crowdsourcing log analysis system and methods for protecting computers and networks from malware attacks by analyzing data log information obtained from a plurality of client network. The client networks are associated with a set of network entities representing a plurality of business units or customers. The system may further comprise a plurality of server machines, each operable to execute a security product associated with a security product vendor and log associated information of at the network entities into at least one log file. The log files may be uploaded onto a breach detection platform for analysis based upon crowdsourcing principles and is operable to generate a risk factor attribute for at least one suspect entity.


