Cross-Customer IOC Correlation for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures are inadequate in detecting malicious email messages, as traditional tools and techniques fail to identify advanced types of malware, leading to prolonged network security threats as infected emails remain dormant in user inboxes for days or weeks, and customers without dedicated email analytic appliances lack the ability to prevent malicious message delivery.

Innovation Solution

A management platform conducts a predictive analysis by correlating indicators of compromise (IOCs) from multiple customers to determine if detected anomalies are caused by a malicious electronic message, using a message analytic appliance to analyze email content and network traffic, and assigns threat levels based on correspondence with known malware, enabling proactive response to potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus and email filtering tools are used, then basic malware detection is provided, but advanced malicious email messages cannot be detected

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddetection coverage against advanced threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the detection function into two parts: traditional email filtering tools handle basic malware detection, while a separate email analytic appliance handles advanced threat detection. This segmentation allows each component to specialize in its strengths without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The email analytic appliance acts as an intermediary between traditional filtering tools and advanced threats. It analyzes email messages that pass through traditional filters and provides additional security layer, effectively bridging the detection gap for sophisticated malware.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated email analytic appliances are deployed, then advanced malware detection is achieved, but device complexity and cost increase

Engineering Contradiction:
Improveadvanced threat detectionVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The email analytic appliance is designed to perform multiple functions: analyzing email messages for malware, detecting indicators of compromise, and providing threat intelligence. This multi-functionality reduces the need for separate specialized devices and simplifies the overall security infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary analysis of email messages using the analytic appliance before they reach users' inboxes. By detecting and blocking malicious messages in advance, the system prevents infections rather than having to respond to them afterward, reducing the need for complex remediation systems.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If customers without email analytic appliances rely on security appliances monitoring network communications, then IOCs can be identified, but malicious email delivery cannot be prevented

Engineering Contradiction:
ImproveIOC detection accuracyVSAvoidmalicious message prevention capability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

Instead of waiting for IOCs to appear in network traffic after infection occurs, the system inverts the approach by analyzing email messages before delivery to detect potential malware and IOCs in advance. This proactive approach prevents malicious message delivery rather than detecting it after the fact.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system uses feedback from detected IOCs and malware patterns to continuously improve its detection algorithms. When new threats are identified, the system learns from these patterns and adjusts its analysis criteria, creating a self-improving detection system that becomes more effective over time.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If malicious email messages are allowed to remain in user inboxes, then delivery is not blocked, but network security is prolonged compromised

Engineering Contradiction:
Improveemail delivery operationVSAvoidsecurity threat persistence duration
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The email analytic appliance performs preliminary analysis of incoming messages and identifies malicious content before it is delivered to user inboxes. By blocking threats in advance, the system eliminates the security risk entirely rather than allowing compromised messages to persist in user environments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system takes preliminary anti-action by preemptively blocking malicious email messages before they can infect user systems. This preventive measure counteracts potential harm before it occurs, rather than responding to infections after they have established themselves in the network.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11019081B1System and method of detecting delivery of malware using cross-customer data
Publication Date: 2021.05.25 MAGENTA SECURITY HOLDINGS LLC
  • US11019081B1 patent drawing
  • US11019081B1 patent drawing
  • US11019081B1 patent drawing

AI summary

According to one embodiment, an electronic device features processing circuitry and memory that includes a first logic and a second logic. When executed by the processing circuitry, the first logic organizes (i) a first plurality of indicators of compromise (IOCs) received from a first source, where the first plurality of IOCs being caused by a known origin of a malicious attack, and (ii) one or more IOCs received from a second source that is different from the first source and an origin of the one or more IOCs is unknown. The second logic conducts a predictive analysis that evaluates whether the one or more IOCs have at least a degree of correlation with the first plurality of IOCs, and determines a threat level. The threat level signifies a degree of confidence that IOCs received from the second source are caused by the known origin of the first plurality of IOCs.