Addressing Subsystem IPv6 Exchange for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods fail to effectively detect and address malware infections in subscriber-side terminal devices that aim to integrate into botnets for unauthorized control, especially when there are no noticeable changes in usage behavior, such as increased data traffic, due to the challenges posed by IPv4 address exhaustion and carrier-grade NAT.

Innovation Solution

The method involves using a specially designed addressing subsystem to return an IPv6 exchange address to infected terminal devices when they initiate a session with a malicious C2 server, allowing for clear identification and automated triggering of measures, even in scenarios without traffic significance changes, by replacing the malicious address with a fictitious IPv6 address that does not connect to the C2 server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional traffic monitoring methods are used to detect malware infections, then infections with noticeable traffic changes can be detected, but infections without traffic significance changes cannot be identified

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The detection system is segmented into multiple independent components: a malicious address database storing known C2 server addresses, a session monitoring module tracking individual device sessions, and an identification module that cross-references sessions against the database. This segmentation allows the system to detect infections through address matching rather than relying solely on traffic pattern analysis, thereby improving detection coverage for subtle infections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an addressing subsystem as an intermediary component that sits between the network traffic and the detection logic. This subsystem maintains the malicious address database and performs the actual matching operation, acting as a mediator that translates complex traffic analysis into simple address comparison operations, thereby enhancing both detection accuracy and coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If carrier-grade NAT is used to manage IPv4 address exhaustion, then multiple devices can share IPv4 addresses, but infected devices cannot be clearly identified

Engineering Contradiction:
Improveavailable IP addressesVSAvoiddevice identification accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent transitions from IPv4 addressing to IPv6 addressing, effectively moving to another dimensional space in the addressing hierarchy. IPv6 provides sufficient unique addresses to assign one to each device, eliminating the need for carrier-grade NAT and its associated identification problems. The addressing subsystem leverages IPv6's hierarchical structure to clearly identify individual devices while maintaining efficient routing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If automated measures are triggered upon detecting malware infections, then response time is reduced, but false positives may cause unnecessary disruptions

Engineering Contradiction:
Improveresponse speedVSAvoiddetection reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary validation by cross-referencing detected sessions against a pre-populated database of malicious addresses before triggering automated measures. This preliminary check ensures that only sessions matching known malicious patterns are flagged, reducing false positives while maintaining rapid response times. The malicious address database serves as a pre-computed reference that enables quick, reliable identification.

Inventive Principle:
Principle #9Preliminary anti-action

4Object-affected harmful factors

If all data traffic from infected devices is blocked, then malware communication is prevented, but legitimate traffic is also disrupted

Engineering Contradiction:
Improvemalware impactVSAvoidservice availability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements selective traffic blocking by identifying specific sessions that communicate with malicious addresses and blocking only those sessions while allowing other traffic from the same device to proceed normally. The system modifies the routing behavior locally for infected sessions rather than applying a blanket block to all traffic from the device, thereby containing malware communication while preserving legitimate service availability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4478661A1Method and system for handling malware infections
Publication Date: 2024.12.18 DEUTSCHE TELEKOM AG
  • EP4478661A1 patent drawingFigure 1
  • EP4478661A1 patent drawing
  • EP4478661A1 patent drawing

AI summary

The invention relates to a solution for handling malware infections in which participant-side terminal equipment (TE) (1) of a communication network or terminal devices operated on it have been infected with malware designed to integrate them into a botnet for the purpose of remote control by a computer-based attack facility (CA) (4). When an internet session is initiated by a TE (1) using a network address of a CA (4) previously identified and registered as malicious by network facilities of an abuse detection and treatment subsystem (MBS) (3) of the network operator, the TE (1) initiating this session is registered as an infected TE (1) under a unique identifier within the communication network for the automated triggering of further technical measures.This is achieved by network facilities (2) of an addressing subsystem ASS returning a defined IPv6 exchange address of the network operator to the TE (1) for the malicious network address of the CA (4) used at the start of the session, thereby causing the TE to specify its own IPv6 address as the sender address when transmitting further session data. This is then registered by specially trained network facilities of the MBS (3) together with a timestamp.