Detecting Malicious Server IP Changes via Response Packet Feature Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malicious websites used for cybercrime continuously change their IP addresses and URLs, making it difficult for existing methods to automatically detect and track them, as they rely on manual reporting of new IPs or URLs.

Innovation Solution

A method and device that acquire and compare feature information from response packets of malicious and comparative websites, calculating similarities between protocol information and determining if the malicious website has changed by giving weights to information likely to be dropped during transmission, with a processor determining the change based on a predetermined value.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual reporting of new IPs or URLs is used, then detection accuracy is maintained, but productivity and response speed deteriorate

Engineering Contradiction:
Improvedetection speedVSAvoidautomation level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system automatically detects and identifies malicious websites by comparing feature information from response packets without requiring manual reporting. The detection system serves itself by autonomously monitoring, comparing, and identifying malicious sites, eliminating the need for human intervention in the detection process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors response packets from websites, compares their feature information against stored malicious website patterns, and provides real-time feedback on potential malicious sites. This feedback loop enables continuous automatic detection and identification of malicious websites as they emerge.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If IP or URL changing is used by malicious websites, then adaptability and evasion capability are improved, but detection difficulty increases

Engineering Contradiction:
Improveevasion capabilityVSAvoiddetection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system extracts and analyzes specific feature information from response packets (such as server headers, protocol versions, and response characteristics) that remain consistent even when IP addresses or URLs change. By focusing on these invariant features, the system can identify malicious websites despite their efforts to evade detection through IP or URL changes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system detects changes in website parameters (IP addresses, URLs) while monitoring for consistent feature patterns in response packets. By analyzing parameter changes alongside feature consistency, the system can identify when a website is attempting to evade detection by changing its surface parameters while maintaining malicious characteristics.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If feature information comparison is performed, then detection accuracy is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the comparison process by analyzing specific feature information categories from response packets separately (such as header fields, protocol information, and response characteristics). This segmentation allows for targeted comparison against stored malicious website patterns, improving detection accuracy while managing processing complexity through focused analysis rather than comprehensive examination.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12132762B2Electronic device and method for detecting malicious server
Publication Date: 2024.10.29 S2W INC
  • US12132762B2 patent drawing
  • US12132762B2 patent drawing
  • US12132762B2 patent drawing

AI summary

Provided are an electronic device and method for detecting a malicious server. The method includes acquiring first feature information of a server Internet protocol (IP) of a malicious website, acquiring second feature information of a server IP of a comparative website, comparing the first feature information with the second feature information, and determining that the malicious website has been changed to the comparative website on the basis of the comparison result.