Detecting Malicious Server IP Changes via Response Packet Feature Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malicious websites used for cybercrime continuously change their IP addresses and URLs, making it difficult for existing methods to automatically detect and track them, as they rely on manual reporting of new IPs or URLs.
Innovation Solution
A method and device that acquire and compare feature information from response packets of malicious and comparative websites, calculating similarities between protocol information and determining if the malicious website has changed by giving weights to information likely to be dropped during transmission, with a processor determining the change based on a predetermined value.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual reporting of new IPs or URLs is used, then detection accuracy is maintained, but productivity and response speed deteriorate
Solution Approach 1:
The system automatically detects and identifies malicious websites by comparing feature information from response packets without requiring manual reporting. The detection system serves itself by autonomously monitoring, comparing, and identifying malicious sites, eliminating the need for human intervention in the detection process.
Solution Approach 2:
The system continuously monitors response packets from websites, compares their feature information against stored malicious website patterns, and provides real-time feedback on potential malicious sites. This feedback loop enables continuous automatic detection and identification of malicious websites as they emerge.
2Adaptability or versatility
If IP or URL changing is used by malicious websites, then adaptability and evasion capability are improved, but detection difficulty increases
Solution Approach 1:
The system extracts and analyzes specific feature information from response packets (such as server headers, protocol versions, and response characteristics) that remain consistent even when IP addresses or URLs change. By focusing on these invariant features, the system can identify malicious websites despite their efforts to evade detection through IP or URL changes.
Solution Approach 2:
The system detects changes in website parameters (IP addresses, URLs) while monitoring for consistent feature patterns in response packets. By analyzing parameter changes alongside feature consistency, the system can identify when a website is attempting to evade detection by changing its surface parameters while maintaining malicious characteristics.
3Measurement precision
If feature information comparison is performed, then detection accuracy is improved, but device complexity and processing requirements increase
Solution Approach 1:
The system segments the comparison process by analyzing specific feature information categories from response packets separately (such as header fields, protocol information, and response characteristics). This segmentation allows for targeted comparison against stored malicious website patterns, improving detection accuracy while managing processing complexity through focused analysis rather than comprehensive examination.
Data Source
AI summary
Provided are an electronic device and method for detecting a malicious server. The method includes acquiring first feature information of a server Internet protocol (IP) of a malicious website, acquiring second feature information of a server IP of a comparative website, comparing the first feature information with the second feature information, and determining that the malicious website has been changed to the comparative website on the basis of the comparison result.


