Graph Inference for Suspicious Domain Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise computer networks face challenges in detecting malware infections, particularly advanced persistent threats (APTs) and new malware strains, due to limited resources and the sophistication of these threats, which often evade traditional security defenses.

Innovation Solution

The implementation of a graph inference algorithm, specifically a belief propagation algorithm, is used to analyze host-domain contacts in a computer network, identifying suspicious domains and allowing the network security system to focus its efforts on affected host devices, thereby enhancing detection and remediation capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security defenses are deployed to protect against malware, then basic security coverage is provided, but sophisticated malware attacks including APTs can evade detection

Engineering Contradiction:
Improvedetection accuracyVSAvoidmalware evasion capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by continuously collecting and analyzing host-domain contact data before malware can fully compromise systems. The graph inference algorithm proactively identifies suspicious domains by analyzing communication patterns, enabling early detection and prevention of malware infections including APTs before they can establish persistent control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transitions from traditional single-dimension signature-based detection to multi-dimensional analysis by constructing graphs that capture complex relationships between hosts, domains, and communication patterns. This dimensional expansion enables the system to detect sophisticated malware that evades conventional defenses by analyzing contextual relationships rather than isolated indicators.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If network security system resources are increased to detect and remediate malware infections, then detection capability improves, but the cost and complexity of the system increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically collecting host-domain contact data, constructing graphs, and executing inference algorithms without requiring extensive manual intervention. The automated pipeline processes security data continuously, identifying suspicious domains and generating remediation recommendations, thereby reducing operational complexity while maintaining high detection reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual security analysis and response mechanisms with automated graph-based inference systems. Instead of relying on security personnel to manually analyze communication patterns and identify threats, the system uses algorithmic processing to automatically detect suspicious domains and generate remediation actions, significantly reducing human resource requirements and system operational complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive security monitoring is applied to all host devices in a large enterprise network, then complete coverage is achieved, but resource strain increases making it difficult to provide desired protection

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts and focuses computational resources on identifying and analyzing suspicious domains rather than uniformly processing all host-device communications. By extracting the critical element (suspicious domain identification) from the complex whole (enterprise network traffic), the system achieves comprehensive security coverage while maintaining performance, as resources are concentrated on high-value threat indicators rather than distributed equally across all traffic.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by tailoring security analysis depth to specific domains identified as suspicious through graph inference. Rather than applying uniform monitoring intensity to all domains, the system dynamically adjusts analysis resources based on risk assessment, concentrating computational power on domains showing malicious characteristics while reducing overhead for benign communications, thereby achieving comprehensive coverage with optimized resource utilization.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9635049B1Detection of suspicious domains through graph inference algorithm processing of host-domain contacts
Publication Date: 2017.04.25 THE CHARLES STARK DRAPER LABORATORY INC
  • US9635049B1 patent drawing
  • US9635049B1 patent drawing
  • US9635049B1 patent drawing

AI summary

A processing device comprises a processor coupled to a memory and is configured to obtain data relating to communications initiated by host devices of a computer network of an enterprise, and to process the data to identify external domains contacted by the host devices. A graph inference algorithm is applied to analyze contacts of the host devices with the external domains in order to characterize one or more of the external domains as suspicious domains. The host devices are configured to counteract malware infection from the suspicious domains. The graph inference algorithm in some embodiments comprises a belief propagation algorithm, which may be initiated with one or more seeds corresponding to respective known suspicious domains or to respective ones of the external domains determined to be associated with command and control behavior. The processing device may be implemented in the computer network or an associated network security system.