Distributed Anomaly Detection for Zero-Day Malware Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying the footprint of malicious software, especially zero-day attacks, are inefficient and require human expertise, often resulting in false positives and inability to accurately detect and remove offending software.

Innovation Solution

A system that detects anomalies in a network, identifies associated features, updates them, and communicates this information across nodes to correlate and determine the presence of malicious software, allowing for automatic identification and removal of undesirable features without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If semi-automated methods like Strider or Triumfant are used to identify malicious software footprint, then more data is provided to specialists, but human expertise is still required and false positives increase

Engineering Contradiction:
Improvecompleteness of attack footprint identificationVSAvoidoperational complexity requiring human expertise
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system enables self-service by implementing automated anomaly detection and footprint identification that operates without human intervention. The distributed network of computing nodes automatically correlates features and identifies malicious software, eliminating the need for human specialists to manually analyze attack footprints while maintaining high accuracy and reducing false positives through collective network intelligence.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If human specialists manually identify malicious software features, then accurate detection is achieved, but the process is painstaking and time-consuming

Engineering Contradiction:
Improveaccuracy of malicious software detectionVSAvoidtime required for identification process
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system replaces the mechanical process of manual human analysis with automated computational mechanisms. Distributed computing nodes automatically detect anomalies, identify features, and correlate data to identify malicious software footprints, achieving both high accuracy and rapid processing without the time-consuming manual intervention previously required by human specialists.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system segments the identification process into distributed tasks performed by multiple independent computing nodes. Each node autonomously detects anomalies and identifies features locally, then contributes findings to the collective network analysis, enabling parallel processing that dramatically reduces identification time while maintaining detection accuracy through distributed intelligence.

Inventive Principle:
Principle #1Segmentation

3Extent of automation

If knowledge bases of known attacks are used for anomaly detection, then automated response is enabled, but zero-day attacks cannot be detected

Engineering Contradiction:
Improveautomation of attack responseVSAvoidcapability to detect zero-day attacks
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic adaptability by using distributed anomaly detection that learns from collective network data rather than relying on static knowledge bases. The distributed network continuously adapts to new attack patterns by correlating features across multiple nodes, enabling automatic detection of zero-day attacks while maintaining automated response capabilities through real-time collective intelligence.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8561179B2Method for identifying undesirable features among computing nodes
Publication Date: 2013.10.15 GENESEE VALLEY INNOVATIONS LLC
  • US8561179B2 patent drawing
  • US8561179B2 patent drawing
  • US8561179B2 patent drawing

AI summary

One embodiment of the present invention provides a system for identifying undesirable features in a network of computers. During operation, the system detects an anomaly associated with a node in the network. Next, the system identifies one or more features which are associated with the anomaly. The system then updates the identified features. Next, the system communicates the information corresponding to updated features to at least one other node in the network. The system then receives information indicating a correlation between the updated features and the anomaly from at least one other node in the network. Next, the system correlates the updated features with the anomaly based on the received information. The system subsequently produces a result which indicates a correlation between the updated features and the anomaly.