Malware Campaign Detection via Composite Time Series Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to efficiently detect malware campaigns from telemetry data due to the complexity and cost of analyzing enriched time series data, often resulting in missed insights into the threat landscape.

Innovation Solution

A system that calculates a target statistic set based on composite time series data from a specific interval and compares it to a historical statistic set from a longer interval, performing peak detection analysis when the target set exceeds a threshold, and sending notifications for valid peak results indicative of malware campaigns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If organizations analyze enriched time series telemetry data to identify malware campaigns, then detection accuracy improves, but analysis cost and complexity increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the analysis process into distinct phases: data collection from multiple sources, feature extraction to identify relevant patterns, statistical analysis to detect anomalies, and incident generation for actionable insights. This segmentation reduces overall complexity by breaking down the overwhelming task of analyzing enriched time series data into manageable, specialized components that can be processed independently and efficiently.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If organizations analyze enriched time series telemetry data to identify malware campaigns, then detection accuracy improves, but resource consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the most relevant features and patterns from the vast telemetry data using feature extraction techniques. Instead of processing all enriched time series data in full detail, the system identifies and extracts key indicators such as statistical deviations, trend changes, and anomaly patterns. This extraction approach maintains high detection accuracy while significantly reducing the computational resources required for analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If peak detection analysis is performed on target statistic set, then malware campaign detection accuracy improves, but false positives increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positives
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where detected peaks and anomalies are validated against multiple criteria before being classified as malware campaigns. The system uses historical data comparison, statistical significance testing, and pattern matching to verify detected peaks. This feedback loop allows the system to distinguish between genuine malware campaign signals and normal traffic variations, improving detection accuracy while reducing false positives through iterative validation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12050684B2Detecting malware campaigns based on analysis of composite time series of telemetry data
Publication Date: 2024.07.30 VMWARE INC
  • US12050684B2 patent drawing
  • US12050684B2 patent drawing
  • US12050684B2 patent drawing

AI summary

The disclosure herein describes the detection of malware campaigns based on analysis of attributes of telemetry data. Telemetry data associated with malware campaign detection includes multiple attributes and is associated with a first time interval. Statistics of a target statistic set are calculated based on a composite time series of the multiple attributes of the telemetry data. The target set is compared to a historical statistic set based on a second time interval and, based on the target set exceeding a statistic threshold of the historical set, peak detection analysis of the target set is performed. Based on the analysis indicating the presence of a valid peak result, a notification of detection of a malware campaign is sent, wherein the notification includes data indicative of the valid peak result and enables a receiver of the notification to take corrective action.