Malicious Protocol Message Format Extraction via Execution Trace Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for analyzing malicious program communication protocols are labor-intensive, inefficient, and prone to high false negative rates due to reliance on manual statistical analysis and human expertise.

Innovation Solution

A method and device that automatically extract the message format of malicious program communication protocols by capturing and analyzing the execution trace of the malicious program client, reducing human intervention and enhancing automation, accuracy, and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual statistical analysis and human expertise are used to analyze communication protocols, then analysis can be performed, but labor investment is large, efficiency is low, and false negative rate is high

Engineering Contradiction:
Improveanalysis efficiencyVSAvoidmanual operation level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system performs self-service by automatically capturing execution traces and extracting message formats without requiring manual intervention. The automated trace capture mechanism records program execution details, and the extraction algorithm processes this data to identify communication protocols, eliminating the need for human analysts to manually examine packets or statistical data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical analysis with automated computational processes. Instead of human analysts manually parsing packets or performing statistical analysis, the system uses automated trace capture and algorithmic extraction to identify message formats, substituting human cognitive processing with machine-based automated systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of time

If manual analysis methods are used, then protocol exploration can be conducted, but analysis time is long

Engineering Contradiction:
Improveanalysis timeVSAvoidextraction efficiency
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The system performs preliminary action by capturing execution traces during program operation, automatically recording the necessary data before analysis is needed. This trace capture occurs in the background as the malicious program executes, so when analysis is required, the data is already prepared and ready for immediate processing, eliminating time-consuming manual data collection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trace capture process operates continuously during program execution, continuously recording execution details without interruption. This continuous automated monitoring ensures that all necessary data is collected in real-time as the program runs, eliminating the discontinuous and time-consuming nature of manual analysis where analysts must stop and examine data at various stages.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If statistical analysis is used to analyze data packets, then protocol patterns can be identified, but false negative rate is high due to reliance on manual interpretation

Engineering Contradiction:
Improvefalse negative rateVSAvoidanalysis accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The execution trace serves as an intermediary that bridges the gap between raw program execution and protocol analysis. Instead of directly analyzing potentially misleading statistical packet data, the system captures detailed execution traces as an intermediate representation, which then provides accurate, context-rich information for reliable message format extraction, eliminating the false negatives caused by manual statistical interpretation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a precise copy of the execution trace that faithfully reproduces the program's behavior and data handling. This accurate copy preserves all contextual information about how the program processes messages, allowing for precise analysis without the errors and misinterpretations that occur when manually analyzing statistical data or packet captures.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9589136B2Method and device for extracting message format
Publication Date: 2017.03.07 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9589136B2 patent drawing
  • US9589136B2 patent drawing
  • US9589136B2 patent drawing

AI summary

Examples of extracting a message format are disclosed. Extracting the message format may include capturing an execution trace of a malicious program client and identifying and analyzing a processing procedure of a message in the execution trace. An input message format is identified based on the analysis, where the input message format is of a communication protocol used by a malicious program. The examples of identifying the message format provide increase extraction efficiency, accurate analysis and positioning, and a reduced rate of false positives.