Log Analytics Malware Detection via Channel Feature Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection systems face challenges in accurately identifying sophisticated threats due to their reliance on traditional signature and sandbox-based approaches, which are often evaded by attackers, and struggle to provide continuous learning and extensive coverage of various malware types, especially with new patterns emerging constantly.

Innovation Solution

A log-analytic detection system that analyzes outbound communication log files to identify security threats by extracting channel and super-channel features, generating risk factors, and blocking malicious entities, utilizing machine learning algorithms for behavioral detection and threat intelligence to provide accurate and automated malware detection across multiple business units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional signature and sandbox-based approaches are used for malware detection, then the system can detect known malware types, but sophisticated adversaries can evade detection by hiding attacks

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidability to detect new malware patterns
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system changes the detection parameters from static signature matching to dynamic behavioral analysis. Instead of detecting malware based on fixed characteristics, the system monitors communication patterns, frequency, timing, and data flow parameters to identify malicious behavior, enabling detection of both known and unknown malware types

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical signature-matching approach with a machine learning-based analytical system. The log-analytic detection platform uses algorithms to automatically analyze communication logs, identify patterns, and detect threats without relying on pre-defined signatures or sandbox execution

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If traditional SIEM solutions are used, then logging and forensics capabilities are provided, but attack detection capability is insufficient

Engineering Contradiction:
Improvelogging and forensics capabilityVSAvoidattack detection capability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The log-analytic detection platform performs multiple functions: it maintains comprehensive logging capabilities for forensics while simultaneously providing real-time attack detection. The system analyzes communication logs to both record events and identify threats, eliminating the need to choose between logging and detection capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If continuous learning processes are applied to discover hidden patterns, then new malware patterns can be detected, but the system complexity increases

Engineering Contradiction:
Improvecontinuous learning and pattern discoveryVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements self-service through automated machine learning processes that continuously analyze communication logs, learn new patterns, and update detection models without manual intervention. The log-analytic detection platform autonomously discovers hidden patterns and adapts to new threats, reducing the need for complex manual configuration and maintenance

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11785035B2System and methods for malware detection using log analytics for channels and super channels
Publication Date: 2023.10.10 RADWARE LTD
  • US11785035B2 patent drawing
  • US11785035B2 patent drawing
  • US11785035B2 patent drawing

AI summary

A method for operating at least one log-analytics detection platform for detecting security threats associated with a client network, comprising: obtaining, via a communication network, log files from a client network, each log file comprising a log record associated with a channel and including an outbound communications log; extracting a channel feature set for said channels from said log files, said channel feature set comprises data pertaining to an associated entity, at least one channel feature being behavior of communication over a channel; aggregating said channel associated features for each of the channels into a data repository; generating a risk factor characterized by an entity score for said least one entity associated with entities of said channels; and blocking of communication for said entity when said risk factory is indicative of said entity being a security threat.