Malicious Server Detection Using Access State Matrices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting malicious servers controlling malware-infected clients have insufficient detection accuracy, particularly when focusing on client behavior such as flow size and access time.
Innovation Solution
A detection device that processes communication information to generate a matrix representing client-server access states, aggregates similar clients to create statistical features, and uses supervised learning to determine if a server is malicious based on these features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If supervised learning scheme focuses on client behavior (flow size, access time), then detection process is simple, but detection accuracy for malicious server becomes insufficient
Solution Approach 1:
The patent transitions from analyzing client behavior in traditional dimensions (flow size, access time) to a new dimensional approach by constructing access state matrices that represent server usage patterns from multiple client perspectives. This dimensional transformation enables the system to capture malicious server characteristics that are invisible in conventional analysis, thereby improving detection accuracy without significantly increasing process complexity.
Solution Approach 2:
The patent changes the analytical parameters from direct client behavior metrics (flow size, access time) to derived server usage pattern parameters (access state matrix representations, similarity statistical information). This parameter transformation allows the system to detect malicious servers by identifying anomalous usage patterns across multiple clients, achieving higher detection accuracy while maintaining reasonable process complexity.
2Ease of manufacture
If focus on client behavior metrics (flow size, access time), then data collection is easy, but detection accuracy for malicious server is insufficient
Solution Approach 1:
The patent performs preliminary actions by constructing access state matrices and calculating similarity statistical information before applying supervised learning. This preprocessing transforms raw client behavior data into structured server usage pattern representations, making the subsequent detection process more accurate. The preliminary transformation of data into meaningful patterns enables high detection accuracy while still starting from easily collectible client behavior metrics.
Solution Approach 2:
The patent introduces access state matrices and similarity statistical information as intermediary representations between raw client behavior data and final malicious server detection. These intermediaries transform simple client behavior metrics into comprehensive server usage patterns, bridging the gap between easy-to-collect data and high-accuracy detection requirements.
3Productivity
If use traditional supervised learning on client behavior, then processing is fast, but detection accuracy for malicious server cannot be improved
Solution Approach 1:
The patent segments the detection process into distinct stages: constructing access state matrices for each server, calculating similarity statistical information, and applying supervised learning. This segmentation allows efficient processing at each stage while progressively building more accurate representations. The modular approach maintains processing speed by breaking down complex analysis into manageable computational tasks that can be executed efficiently.
Solution Approach 2:
The patent performs preliminary computations (matrix construction, similarity calculations) before the supervised learning stage, preparing optimized input data structures. This preliminary action ensures that the main learning process receives pre-processed, high-quality inputs, maintaining fast processing speed while achieving improved detection accuracy through better feature representation.
Data Source
AI summary
A detection device includes processing circuitry configured to collect communication information in a network including clients and servers, generate a matrix representing states of access from the clients to the servers using the communication information collected, aggregate a plurality of the clients accessing a target server and generate statistical information of similarities between the aggregated clients in the matrix as a feature amount of the target server, learn, with regard to the target server which is a server for which it is known whether the server is a malicious server, a model for determining whether a server is a malicious server using the feature amount generated, and determine, with regard to the target server which is a server for which it is unknown whether the server is a malicious server, whether the target server is a malicious server using the feature amount generated and the model.


