Log Analytics Malware Detection via Channel Feature Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection systems face challenges in accurately identifying sophisticated threats due to their reliance on traditional signature and sandbox-based approaches, which are often evaded by attackers, and struggle to provide continuous learning and extensive coverage of various malware types, especially with new patterns emerging constantly.
Innovation Solution
A log-analytic detection system that analyzes outbound communication log files to identify security threats by extracting channel and super-channel features, generating risk factors, and blocking malicious entities, utilizing machine learning algorithms for behavioral detection and threat intelligence to provide accurate and automated malware detection across multiple business units.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional signature and sandbox-based approaches are used for malware detection, then the system can detect known malware types, but sophisticated adversaries can evade detection by hiding attacks
Solution Approach 1:
The system changes the detection parameters from static signature matching to dynamic behavioral analysis. Instead of detecting malware based on fixed characteristics, the system monitors communication patterns, frequency, timing, and data flow parameters to identify malicious behavior, enabling detection of both known and unknown malware types
Solution Approach 2:
The patent replaces the mechanical signature-matching approach with a machine learning-based analytical system. The log-analytic detection platform uses algorithms to automatically analyze communication logs, identify patterns, and detect threats without relying on pre-defined signatures or sandbox execution
2Loss of information
If traditional SIEM solutions are used, then logging and forensics capabilities are provided, but attack detection capability is insufficient
Solution Approach 1:
The log-analytic detection platform performs multiple functions: it maintains comprehensive logging capabilities for forensics while simultaneously providing real-time attack detection. The system analyzes communication logs to both record events and identify threats, eliminating the need to choose between logging and detection capabilities
3Adaptability or versatility
If continuous learning processes are applied to discover hidden patterns, then new malware patterns can be detected, but the system complexity increases
Solution Approach 1:
The system implements self-service through automated machine learning processes that continuously analyze communication logs, learn new patterns, and update detection models without manual intervention. The log-analytic detection platform autonomously discovers hidden patterns and adapts to new threats, reducing the need for complex manual configuration and maintenance
Data Source
AI summary
A method for operating at least one log-analytics detection platform for detecting security threats associated with a client network, comprising: obtaining, via a communication network, log files from a client network, each log file comprising a log record associated with a channel and including an outbound communications log; extracting a channel feature set for said channels from said log files, said channel feature set comprises data pertaining to an associated entity, at least one channel feature being behavior of communication over a channel; aggregating said channel associated features for each of the channels into a data repository; generating a risk factor characterized by an entity score for said least one entity associated with entities of said channels; and blocking of communication for said entity when said risk factory is indicative of said entity being a security threat.


