Malware Campaign Detection via Composite Time Series Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to efficiently detect malware campaigns from telemetry data due to the complexity and cost of analyzing enriched time series data, often resulting in missed insights into the threat landscape.
Innovation Solution
A system that calculates a target statistic set based on composite time series data from a specific interval and compares it to a historical statistic set from a longer interval, performing peak detection analysis when the target set exceeds a threshold, and sending notifications for valid peak results indicative of malware campaigns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If organizations analyze enriched time series telemetry data to identify malware campaigns, then detection accuracy improves, but analysis cost and complexity increase
Solution Approach 1:
The patent segments the analysis process into distinct phases: data collection from multiple sources, feature extraction to identify relevant patterns, statistical analysis to detect anomalies, and incident generation for actionable insights. This segmentation reduces overall complexity by breaking down the overwhelming task of analyzing enriched time series data into manageable, specialized components that can be processed independently and efficiently.
2Measurement precision
If organizations analyze enriched time series telemetry data to identify malware campaigns, then detection accuracy improves, but resource consumption increases
Solution Approach 1:
The patent extracts only the most relevant features and patterns from the vast telemetry data using feature extraction techniques. Instead of processing all enriched time series data in full detail, the system identifies and extracts key indicators such as statistical deviations, trend changes, and anomaly patterns. This extraction approach maintains high detection accuracy while significantly reducing the computational resources required for analysis.
3Measurement precision
If peak detection analysis is performed on target statistic set, then malware campaign detection accuracy improves, but false positives increase
Solution Approach 1:
The patent implements feedback mechanisms where detected peaks and anomalies are validated against multiple criteria before being classified as malware campaigns. The system uses historical data comparison, statistical significance testing, and pattern matching to verify detected peaks. This feedback loop allows the system to distinguish between genuine malware campaign signals and normal traffic variations, improving detection accuracy while reducing false positives through iterative validation.
Data Source
AI summary
The disclosure herein describes the detection of malware campaigns based on analysis of attributes of telemetry data. Telemetry data associated with malware campaign detection includes multiple attributes and is associated with a first time interval. Statistics of a target statistic set are calculated based on a composite time series of the multiple attributes of the telemetry data. The target set is compared to a historical statistic set based on a second time interval and, based on the target set exceeding a statistic threshold of the historical set, peak detection analysis of the target set is performed. Based on the analysis indicating the presence of a valid peak result, a notification of detection of a malware campaign is sent, wherein the notification includes data indicative of the valid peak result and enables a receiver of the notification to take corrective action.


