Log Analysis Device Malware Signature Enrichment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional malware detection techniques face challenges in providing operators with sufficient information to determine appropriate actions based on detection results, as they only notify of detection results and signatures without specifying necessary actions.
Innovation Solution
A log analysis device and method that acquires communication logs, generates signatures for malware detection, adds malware information to these signatures, and displays detection results associated with the used signatures, enabling operators to take informed actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional log analysis techniques notify operators of detection results and signatures, then detection capability is achieved, but operators lack sufficient information to determine appropriate actions
Solution Approach 1:
The system performs preliminary analysis by automatically determining appropriate actions based on detection results before presenting information to the operator. The action determination unit pre-processes detection results to identify recommended actions, reducing the operator's cognitive burden and enabling faster decision-making with complete information already prepared.
Solution Approach 2:
The action determination unit serves as an intermediary between the detection result and the operator. It translates raw detection data into actionable recommendations, bridging the information gap and enabling operators to make informed decisions without needing to interpret complex technical details themselves.
2Loss of information
If detailed malware information is added to signatures, then operator decision-making is improved, but system complexity increases
Solution Approach 1:
The system segments information processing into distinct functional units: detection unit for identifying malware, information addition unit for attaching relevant malware details, and action determination unit for recommending actions. This modular segmentation allows comprehensive information to be processed without overwhelming system complexity, as each unit handles specific tasks independently.
Solution Approach 2:
The system changes parameters by selectively adding only relevant malware information parameters to signatures based on the detection context. Rather than adding all possible malware data, the system dynamically determines which parameters (e.g., malware type, severity level, affected systems) are most useful for action determination, optimizing the balance between information completeness and processing efficiency.
Data Source
AI summary
A log acquirer acquires an analysis communication log and a malicious communication log. A signature generator generates a signature serving as a condition for detecting a terminal infected with malware based on a field and a value included in the malicious communication log. A malware analysis report acquirer acquires information on the malware. A malware information adder adds the information on the malware to the signature. A log analyzer analyzes the analysis communication log using the signature and detects the terminal infected with the malware. A detection result display unit displays the detection result obtained from the analysis communication log by the log analyzer and the information on the malware added to the signature used in the analysis of the analysis communication log in a manner associated with each other.


