Malicious Event Detection via Traffic Replay and Feature Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques face challenges in efficiently analyzing events sensed by security instruments due to the large number of uncorrelated events, including those not related to malware communication, leading to increased operational time and cost, and difficulties in detecting malware-infected terminals, especially with techniques relying on whitelisting or urgency-based filtering.
Innovation Solution
A malicious event detection system comprising a reading unit, generation unit, collection unit, extraction unit, and determination unit that reads and generates traffic files, collects events, extracts features, and determines whether events are malicious or benign based on these features, allowing for automated classification and efficient analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a large number of different types of events are directly presented to an operator for manual analysis, then complete event analysis is achieved, but the time necessary to specify a malware-infected terminal and the cost of operation increase
Solution Approach 1:
The system enables automatic event analysis by having the security instrument itself generate features and perform determination on events, eliminating the need for manual operator analysis while maintaining complete event examination capabilities
Solution Approach 2:
The patent replaces manual operator analysis with an automated determination unit that uses machine learning models to classify events as malicious or benign, substituting human cognitive processing with computational algorithms
2Productivity
If events are reduced to be analyzed by registering unaffected events in a whitelist and extracting events other than those in the whitelist, then the number of events to analyze decreases, but when new threats appear one after another and the type of the event increases, the number of events does not decrease
Solution Approach 1:
The system changes the approach from static whitelist filtering to dynamic feature extraction and machine learning-based classification, allowing the system to adapt to new event types by learning from data rather than relying on pre-defined categories
Solution Approach 2:
The patent replaces the mechanical whitelist filtering system with an intelligent determination unit that uses machine learning models to automatically identify and classify new event types as they emerge, providing continuous adaptation without manual rule updates
3Productivity
If only events whose degree of urgency, which has been given to each event, is equal to or greater than a predetermined level are extracted and analyzed, then the number of events to analyze decreases, but there are cases where, among events that characterize infection of malware, an event whose given degree of urgency is not equal to or greater than a predetermined level is inadvertently overlooked
Solution Approach 1:
The system changes from threshold-based urgency filtering to a comprehensive feature extraction approach where multiple event characteristics are analyzed together, allowing low-urgency events to be detected through their pattern recognition and contextual relationships
Solution Approach 2:
The patent merges multiple analysis dimensions including feature extraction, machine learning classification, and pattern recognition into a unified determination system that evaluates events holistically rather than through single criteria filtering
Data Source
AI summary
A playback device reads a traffic file which is a dump file of traffic when malicious or benign traffic is generated and generates traffic based on the traffic file on a network having a security instrument that generates an event in accordance with the traffic. In addition, a determination device collects an event generated by the security instrument for the generated traffic and, on the basis of a feature extracted from the collected event, determines whether the event to be determined is for malicious traffic or benign traffic.


