Malicious Server Detection Using Access State Matrices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting malicious servers controlling malware-infected clients have insufficient detection accuracy, particularly when focusing on client behavior such as flow size and access time.

Innovation Solution

A detection device that processes communication information to generate a matrix representing client-server access states, aggregates similar clients to create statistical features, and uses supervised learning to determine if a server is malicious based on these features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If supervised learning scheme focuses on client behavior (flow size, access time), then detection process is simple, but detection accuracy for malicious server becomes insufficient

Engineering Contradiction:
Improvedetection process complexityVSAvoiddetection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent transitions from analyzing client behavior in traditional dimensions (flow size, access time) to a new dimensional approach by constructing access state matrices that represent server usage patterns from multiple client perspectives. This dimensional transformation enables the system to capture malicious server characteristics that are invisible in conventional analysis, thereby improving detection accuracy without significantly increasing process complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent changes the analytical parameters from direct client behavior metrics (flow size, access time) to derived server usage pattern parameters (access state matrix representations, similarity statistical information). This parameter transformation allows the system to detect malicious servers by identifying anomalous usage patterns across multiple clients, achieving higher detection accuracy while maintaining reasonable process complexity.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If focus on client behavior metrics (flow size, access time), then data collection is easy, but detection accuracy for malicious server is insufficient

Engineering Contradiction:
Improvedata collection easeVSAvoiddetection accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent performs preliminary actions by constructing access state matrices and calculating similarity statistical information before applying supervised learning. This preprocessing transforms raw client behavior data into structured server usage pattern representations, making the subsequent detection process more accurate. The preliminary transformation of data into meaningful patterns enables high detection accuracy while still starting from easily collectible client behavior metrics.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces access state matrices and similarity statistical information as intermediary representations between raw client behavior data and final malicious server detection. These intermediaries transform simple client behavior metrics into comprehensive server usage patterns, bridging the gap between easy-to-collect data and high-accuracy detection requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If use traditional supervised learning on client behavior, then processing is fast, but detection accuracy for malicious server cannot be improved

Engineering Contradiction:
Improveprocessing speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent segments the detection process into distinct stages: constructing access state matrices for each server, calculating similarity statistical information, and applying supervised learning. This segmentation allows efficient processing at each stage while progressively building more accurate representations. The modular approach maintains processing speed by breaking down complex analysis into manageable computational tasks that can be executed efficiently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary computations (matrix construction, similarity calculations) before the supervised learning stage, preparing optimized input data structures. This preliminary action ensures that the main learning process receives pre-processed, high-quality inputs, maintaining fast processing speed while achieving improved detection accuracy through better feature representation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12028356B2Detection device, detection method, and detection program
Publication Date: 2024.07.02 NIPPON TELEGRAPH & TELEPHONE CORP
  • US12028356B2 patent drawing
  • US12028356B2 patent drawing
  • US12028356B2 patent drawing

AI summary

A detection device includes processing circuitry configured to collect communication information in a network including clients and servers, generate a matrix representing states of access from the clients to the servers using the communication information collected, aggregate a plurality of the clients accessing a target server and generate statistical information of similarities between the aggregated clients in the matrix as a feature amount of the target server, learn, with regard to the target server which is a server for which it is known whether the server is a malicious server, a model for determining whether a server is a malicious server using the feature amount generated, and determine, with regard to the target server which is a server for which it is unknown whether the server is a malicious server, whether the target server is a malicious server using the feature amount generated and the model.