Malware-Infected Device Identification via Domain Dissimilarity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods fail to reliably distinguish between benign and malicious domain names generated by Domain Generation Algorithms (DGAs) used by botnets, leading to high false positive or low true positive rates in identifying malware-infected devices.
Innovation Solution
An infected device identification engine processes DNS messages to determine dissimilarities between domain names, aggregates these dissimilarities, and compares them to a threshold to identify malware-infected devices, using techniques such as edit distance metrics and whitelisting to differentiate between benign and malicious domain names.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Domain Generation Algorithms (DGAs) are used by botnets to generate domain names, then the malware can establish communication with Command and Control servers, but current methods fail to reliably distinguish between benign and malicious domain names, leading to high false positive or low true positive rates in identifying malware-infected devices
Solution Approach 1:
The patent applies parameter changes by analyzing multiple attributes of domain names including length, character composition, and dissimilarity metrics. The system calculates dissimilarity between domain names using edit distance and compares aggregated dissimilarity values against thresholds to dynamically identify malicious patterns, thereby improving both reliability and precision in malware detection
Solution Approach 2:
The patent implements partial action by focusing on specific critical parameters of domain names rather than analyzing all possible attributes. It selectively measures dissimilarity based on key characteristics such as character composition and structural patterns, enabling efficient and accurate detection without unnecessary computational overhead
2Productivity
If current methods are used to identify malware-infected devices, then some detections can be made, but false positive rates are high and true positive rates are low
Solution Approach 1:
The patent implements feedback mechanisms by continuously monitoring domain name patterns and adjusting detection thresholds based on observed dissimilarity metrics. The system uses aggregated dissimilarity measurements to refine its identification criteria, creating a feedback loop that improves detection accuracy while maintaining high productivity in identifying malware-infected devices
Data Source
AI summary
In some examples, for a device that transmitted domain names, a system determines a dissimilarity between the domain names, compares a value derived from the determined dissimilarity to a threshold, and identifies the device as malware infected in response to the comparing.


