Malicious Protocol Message Format Extraction via Execution Trace Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for analyzing malicious program communication protocols are labor-intensive, inefficient, and prone to high false negative rates due to reliance on manual statistical analysis and human expertise.
Innovation Solution
A method and device that automatically extract the message format of malicious program communication protocols by capturing and analyzing the execution trace of the malicious program client, reducing human intervention and enhancing automation, accuracy, and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual statistical analysis and human expertise are used to analyze communication protocols, then analysis can be performed, but labor investment is large, efficiency is low, and false negative rate is high
Solution Approach 1:
The system performs self-service by automatically capturing execution traces and extracting message formats without requiring manual intervention. The automated trace capture mechanism records program execution details, and the extraction algorithm processes this data to identify communication protocols, eliminating the need for human analysts to manually examine packets or statistical data.
Solution Approach 2:
The patent replaces manual mechanical analysis with automated computational processes. Instead of human analysts manually parsing packets or performing statistical analysis, the system uses automated trace capture and algorithmic extraction to identify message formats, substituting human cognitive processing with machine-based automated systems.
2Loss of time
If manual analysis methods are used, then protocol exploration can be conducted, but analysis time is long
Solution Approach 1:
The system performs preliminary action by capturing execution traces during program operation, automatically recording the necessary data before analysis is needed. This trace capture occurs in the background as the malicious program executes, so when analysis is required, the data is already prepared and ready for immediate processing, eliminating time-consuming manual data collection.
Solution Approach 2:
The trace capture process operates continuously during program execution, continuously recording execution details without interruption. This continuous automated monitoring ensures that all necessary data is collected in real-time as the program runs, eliminating the discontinuous and time-consuming nature of manual analysis where analysts must stop and examine data at various stages.
3Reliability
If statistical analysis is used to analyze data packets, then protocol patterns can be identified, but false negative rate is high due to reliance on manual interpretation
Solution Approach 1:
The execution trace serves as an intermediary that bridges the gap between raw program execution and protocol analysis. Instead of directly analyzing potentially misleading statistical packet data, the system captures detailed execution traces as an intermediate representation, which then provides accurate, context-rich information for reliable message format extraction, eliminating the false negatives caused by manual statistical interpretation.
Solution Approach 2:
The system creates a precise copy of the execution trace that faithfully reproduces the program's behavior and data handling. This accurate copy preserves all contextual information about how the program processes messages, allowing for precise analysis without the errors and misinterpretations that occur when manually analyzing statistical data or packet captures.
Data Source
AI summary
Examples of extracting a message format are disclosed. Extracting the message format may include capturing an execution trace of a malicious program client and identifying and analyzing a processing procedure of a message in the execution trace. An input message format is identified based on the analysis, where the input message format is of a communication protocol used by a malicious program. The examples of identifying the message format provide increase extraction efficiency, accurate analysis and positioning, and a reduced rate of false positives.


