Distributed Traffic Pattern Analysis for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection techniques are inadequate in detecting unknown malware, as they rely on signature-based methods that can be evaded by malicious software, and lack sufficient contextual knowledge of the affected system, leading to incomplete protection of computers and networks.

Innovation Solution

A distributed traffic pattern analysis and entropy prediction system that monitors network traffic and behavioral changes in potentially affected systems, using genetic programs to predict normal traffic patterns and compare them to actual traffic, enabling detection of malware without relying on specific threat signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based malware detection methods are used, then detection of known malware is improved, but detection of unknown malware deteriorates

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddetection capability against unknown malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transforms the detection approach from signature-based (static) to behavior-based (dynamic) by monitoring network traffic parameters and system behavioral patterns. This allows the system to detect unknown malware by analyzing deviations from normal behavior patterns rather than relying on predefined signatures.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical signature-matching system with an intelligent behavior analysis system that uses machine learning and pattern recognition algorithms to detect malware based on behavioral characteristics, enabling detection of previously unknown threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If distributed traffic pattern analysis is implemented, then detection capability for unknown malware is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the malware detection system into distributed components that monitor different aspects of network traffic and system behavior independently. Each component analyzes specific patterns and reports findings to a central coordination system, reducing individual component complexity while maintaining overall detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a multi-functional detection system that can identify various types of malware (viruses, worms, trojans, ransomware) using a single unified approach based on behavioral analysis and traffic pattern recognition, eliminating the need for separate detection mechanisms for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If contextual knowledge is enhanced for better malware detection, then detection accuracy is improved, but information processing requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidinformation processing load
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the most relevant contextual information needed for malware detection from the vast amount of available system data. By focusing on critical behavioral patterns and traffic characteristics rather than processing all possible information, the system maintains high detection accuracy while reducing processing load.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements monitoring at strategic points in the network and system architecture to capture sufficient behavioral data for detection without comprehensively analyzing every byte of traffic or every system event, achieving effective detection with reduced processing requirements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10027695B2Distributed traffic pattern analysis and entropy prediction for detecting malware in a network environment
Publication Date: 2018.07.17 INTEL CORP
  • US10027695B2 patent drawing
  • US10027695B2 patent drawing
  • US10027695B2 patent drawing

AI summary

Technologies are provided in embodiments to detect malware. Embodiments are to receive context information related to a potentially affected system, create a prediction of normal traffic based, at least in part, on the received context information, compare network traffic associated with the potentially affected system to the prediction of normal traffic, and take an action based, at least in part, on the comparison. The action may be taken if the network traffic is not within an acceptable deviation range of the prediction of normal traffic or the action may be taken based on a degree of deviation of the network traffic from the prediction of normal traffic. The acceptable deviation range and the degree of deviation are based, at least in part, on a type of network traffic. The acceptable deviation range and the degree of deviation are based, at least in part, on a volume of network traffic.