Log Analysis Device Malware Signature Enrichment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware detection techniques face challenges in providing operators with sufficient information to determine appropriate actions based on detection results, as they only notify of detection results and signatures without specifying necessary actions.

Innovation Solution

A log analysis device and method that acquires communication logs, generates signatures for malware detection, adds malware information to these signatures, and displays detection results associated with the used signatures, enabling operators to take informed actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional log analysis techniques notify operators of detection results and signatures, then detection capability is achieved, but operators lack sufficient information to determine appropriate actions

Engineering Contradiction:
Improveinformation completeness for operator decision-makingVSAvoidoperator ability to determine actions
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system performs preliminary analysis by automatically determining appropriate actions based on detection results before presenting information to the operator. The action determination unit pre-processes detection results to identify recommended actions, reducing the operator's cognitive burden and enabling faster decision-making with complete information already prepared.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The action determination unit serves as an intermediary between the detection result and the operator. It translates raw detection data into actionable recommendations, bridging the information gap and enabling operators to make informed decisions without needing to interpret complex technical details themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If detailed malware information is added to signatures, then operator decision-making is improved, but system complexity increases

Engineering Contradiction:
Improvemalware information availabilityVSAvoidsystem processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments information processing into distinct functional units: detection unit for identifying malware, information addition unit for attaching relevant malware details, and action determination unit for recommending actions. This modular segmentation allows comprehensive information to be processed without overwhelming system complexity, as each unit handles specific tasks independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes parameters by selectively adding only relevant malware information parameters to signatures based on the detection context. Rather than adding all possible malware data, the system dynamically determines which parameters (e.g., malware type, severity level, affected systems) are most useful for action determination, optimizing the balance between information completeness and processing efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11356467B2Log analysis device, log analysis method, and log analysis program
Publication Date: 2022.06.07 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11356467B2 patent drawing
  • US11356467B2 patent drawing
  • US11356467B2 patent drawing

AI summary

A log acquirer acquires an analysis communication log and a malicious communication log. A signature generator generates a signature serving as a condition for detecting a terminal infected with malware based on a field and a value included in the malicious communication log. A malware analysis report acquirer acquires information on the malware. A malware information adder adds the information on the malware to the signature. A log analyzer analyzes the analysis communication log using the signature and detects the terminal infected with the malware. A detection result display unit displays the detection result obtained from the analysis communication log by the log analyzer and the information on the malware added to the signature used in the analysis of the analysis communication log in a manner associated with each other.