Malicious Event Detection via Traffic Replay and Feature Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques face challenges in efficiently analyzing events sensed by security instruments due to the large number of uncorrelated events, including those not related to malware communication, leading to increased operational time and cost, and difficulties in detecting malware-infected terminals, especially with techniques relying on whitelisting or urgency-based filtering.

Innovation Solution

A malicious event detection system comprising a reading unit, generation unit, collection unit, extraction unit, and determination unit that reads and generates traffic files, collects events, extracts features, and determines whether events are malicious or benign based on these features, allowing for automated classification and efficient analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a large number of different types of events are directly presented to an operator for manual analysis, then complete event analysis is achieved, but the time necessary to specify a malware-infected terminal and the cost of operation increase

Engineering Contradiction:
Improveevent analysis completenessVSAvoidtime to specify malware-infected terminal
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automatic event analysis by having the security instrument itself generate features and perform determination on events, eliminating the need for manual operator analysis while maintaining complete event examination capabilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual operator analysis with an automated determination unit that uses machine learning models to classify events as malicious or benign, substituting human cognitive processing with computational algorithms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If events are reduced to be analyzed by registering unaffected events in a whitelist and extracting events other than those in the whitelist, then the number of events to analyze decreases, but when new threats appear one after another and the type of the event increases, the number of events does not decrease

Engineering Contradiction:
Improveevent analysis efficiencyVSAvoidcapability to handle new event types
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system changes the approach from static whitelist filtering to dynamic feature extraction and machine learning-based classification, allowing the system to adapt to new event types by learning from data rather than relying on pre-defined categories

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical whitelist filtering system with an intelligent determination unit that uses machine learning models to automatically identify and classify new event types as they emerge, providing continuous adaptation without manual rule updates

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If only events whose degree of urgency, which has been given to each event, is equal to or greater than a predetermined level are extracted and analyzed, then the number of events to analyze decreases, but there are cases where, among events that characterize infection of malware, an event whose given degree of urgency is not equal to or greater than a predetermined level is inadvertently overlooked

Engineering Contradiction:
Improveevent analysis efficiencyVSAvoidmalware detection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system changes from threshold-based urgency filtering to a comprehensive feature extraction approach where multiple event characteristics are analyzed together, allowing low-urgency events to be detected through their pattern recognition and contextual relationships

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent merges multiple analysis dimensions including feature extraction, machine learning classification, and pattern recognition into a unified determination system that evaluates events holistically rather than through single criteria filtering

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10963562B2Malicious event detection device, malicious event detection method, and malicious event detection program
Publication Date: 2021.03.30 NIPPON TELEGRAPH & TELEPHONE CORP
  • US10963562B2 patent drawing
  • US10963562B2 patent drawing
  • US10963562B2 patent drawing

AI summary

A playback device reads a traffic file which is a dump file of traffic when malicious or benign traffic is generated and generates traffic based on the traffic file on a network having a security instrument that generates an event in accordance with the traffic. In addition, a determination device collects an event generated by the security instrument for the generated traffic and, on the basis of a feature extracted from the collected event, determines whether the event to be determined is for malicious traffic or benign traffic.