Distributed Traffic Pattern Analysis for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection techniques are inadequate in detecting unknown malware, as they rely on signature-based methods that can be evaded by malicious software, and lack sufficient contextual knowledge of the affected system, leading to incomplete protection of computers and networks.
Innovation Solution
A distributed traffic pattern analysis and entropy prediction system that monitors network traffic and behavioral changes in potentially affected systems, using genetic programs to predict normal traffic patterns and compare them to actual traffic, enabling detection of malware without relying on specific threat signatures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If signature-based malware detection methods are used, then detection of known malware is improved, but detection of unknown malware deteriorates
Solution Approach 1:
The patent transforms the detection approach from signature-based (static) to behavior-based (dynamic) by monitoring network traffic parameters and system behavioral patterns. This allows the system to detect unknown malware by analyzing deviations from normal behavior patterns rather than relying on predefined signatures.
Solution Approach 2:
The patent replaces the mechanical signature-matching system with an intelligent behavior analysis system that uses machine learning and pattern recognition algorithms to detect malware based on behavioral characteristics, enabling detection of previously unknown threats.
2Adaptability or versatility
If distributed traffic pattern analysis is implemented, then detection capability for unknown malware is improved, but system complexity increases
Solution Approach 1:
The patent divides the malware detection system into distributed components that monitor different aspects of network traffic and system behavior independently. Each component analyzes specific patterns and reports findings to a central coordination system, reducing individual component complexity while maintaining overall detection capability.
Solution Approach 2:
The patent creates a multi-functional detection system that can identify various types of malware (viruses, worms, trojans, ransomware) using a single unified approach based on behavioral analysis and traffic pattern recognition, eliminating the need for separate detection mechanisms for each threat type.
3Measurement precision
If contextual knowledge is enhanced for better malware detection, then detection accuracy is improved, but information processing requirements increase
Solution Approach 1:
The patent extracts only the most relevant contextual information needed for malware detection from the vast amount of available system data. By focusing on critical behavioral patterns and traffic characteristics rather than processing all possible information, the system maintains high detection accuracy while reducing processing load.
Solution Approach 2:
The patent implements monitoring at strategic points in the network and system architecture to capture sufficient behavioral data for detection without comprehensively analyzing every byte of traffic or every system event, achieving effective detection with reduced processing requirements.
Data Source
AI summary
Technologies are provided in embodiments to detect malware. Embodiments are to receive context information related to a potentially affected system, create a prediction of normal traffic based, at least in part, on the received context information, compare network traffic associated with the potentially affected system to the prediction of normal traffic, and take an action based, at least in part, on the comparison. The action may be taken if the network traffic is not within an acceptable deviation range of the prediction of normal traffic or the action may be taken based on a degree of deviation of the network traffic from the prediction of normal traffic. The acceptable deviation range and the degree of deviation are based, at least in part, on a type of network traffic. The acceptable deviation range and the degree of deviation are based, at least in part, on a volume of network traffic.


