Malware Detection Agent Using Neutral Security Service Provider

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for detecting client participation in malware activity during denial of service attacks are often costly, one-sided, and difficult to implement, especially in scenarios where compromised machines are involved, and establishing trust relationships between ISPs and clients is challenging.

Innovation Solution

A method and system that utilizes a security service provider and an agent on the client system to share attack information, allowing for local diagnosis of potential malware activity without requiring trust relationships, using historical data and operational information to determine if the client system is an attack source, and enabling local actions to mitigate the issue.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If blocking a compromised machine from the designated target is performed, then the attack occurrence is reduced, but it requires establishing trust relationships between ISP and client which is difficult to establish

Engineering Contradiction:
Improveattack mitigation effectivenessVSAvoidtrust relationship establishment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a neutral third-party security service provider as an intermediary that collects attack information from multiple sources and provides it to clients. This mediator bypasses the need for direct trust relationships between ISPs and clients, as the security service provider independently verifies and shares attack information with all participants on a neutral platform.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If attack information is shared between security service provider and client system, then detection accuracy is improved, but implementation cost increases

Engineering Contradiction:
Improveattack source detection accuracyVSAvoidimplementation cost
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The security service provider operates as a universal platform that serves multiple clients simultaneously, collecting and analyzing attack information from various sources and distributing it to all subscribed clients. This multi-functional approach amortizes the implementation cost across multiple users while maintaining high detection accuracy through centralized intelligence gathering.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If direct communication between compromised machine and attack target is performed, then attack detection is simplified, but the attack source cannot be identified when traffic is insignificant and malware is not identifiable

Engineering Contradiction:
Improvedetection system complexityVSAvoidattack source identification capability
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent merges multiple detection approaches by combining direct monitoring between attack targets and potential compromised machines with centralized collection of attack information from multiple sources. This combination enables the system to identify attack sources even when individual traffic patterns are insignificant, by aggregating evidence from multiple perspectives through the neutral security service provider.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11050783B2System and method for detecting client participation in malware activity
Publication Date: 2021.06.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11050783B2 patent drawing
  • US11050783B2 patent drawing
  • US11050783B2 patent drawing

AI summary

A malware detection method for detecting client participation in malware activity, in respect of a target subjected to a given attack by a client system, which is operable to run a given host application is disclosed a given security service provider is configured, which is operably coupled to the client system, to make accessible given attack information that is reported by a given attack target. An attack status query is transmitted to the security service provider from an agent that is operably coupled to the client system. In response to receiving the attack status query, the security service provider is configured to send attack information reported in respect of a given attack target to the agent, and configuring the agent to diagnose whether its corresponding client system potentially comprises an attack source of the given attack subjected on the attack target, on a basis of the received attack information.