Malware-Infected Device Identification via Domain Dissimilarity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods fail to reliably distinguish between benign and malicious domain names generated by Domain Generation Algorithms (DGAs) used by botnets, leading to high false positive or low true positive rates in identifying malware-infected devices.

Innovation Solution

An infected device identification engine processes DNS messages to determine dissimilarities between domain names, aggregates these dissimilarities, and compares them to a threshold to identify malware-infected devices, using techniques such as edit distance metrics and whitelisting to differentiate between benign and malicious domain names.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Domain Generation Algorithms (DGAs) are used by botnets to generate domain names, then the malware can establish communication with Command and Control servers, but current methods fail to reliably distinguish between benign and malicious domain names, leading to high false positive or low true positive rates in identifying malware-infected devices

Engineering Contradiction:
Improvereliability of identifying malware-infected devicesVSAvoidprecision in distinguishing benign and malicious domain names
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies parameter changes by analyzing multiple attributes of domain names including length, character composition, and dissimilarity metrics. The system calculates dissimilarity between domain names using edit distance and compares aggregated dissimilarity values against thresholds to dynamically identify malicious patterns, thereby improving both reliability and precision in malware detection

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements partial action by focusing on specific critical parameters of domain names rather than analyzing all possible attributes. It selectively measures dissimilarity based on key characteristics such as character composition and structural patterns, enabling efficient and accurate detection without unnecessary computational overhead

Inventive Principle:
Principle #16Partial or excessive action

2Productivity

If current methods are used to identify malware-infected devices, then some detections can be made, but false positive rates are high and true positive rates are low

Engineering Contradiction:
Improvedetection rate of malware-infected devicesVSAvoidaccuracy of malware detection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms by continuously monitoring domain name patterns and adjusting detection thresholds based on observed dissimilarity metrics. The system uses aggregated dissimilarity measurements to refine its identification criteria, creating a feedback loop that improves detection accuracy while maintaining high productivity in identifying malware-infected devices

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10911481B2Malware-infected device identifications
Publication Date: 2021.02.02 MICRO FOCUS LLC
  • US10911481B2 patent drawing
  • US10911481B2 patent drawing
  • US10911481B2 patent drawing

AI summary

In some examples, for a device that transmitted domain names, a system determines a dissimilarity between the domain names, compares a value derived from the determined dissimilarity to a threshold, and identifies the device as malware infected in response to the comparing.