Malware Detection via Dialog Correlation Matrix
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional intrusion detection systems (IDSs) and intrusion prevention systems (IPSs) fail to accurately detect botnet infections and predict the order and time-window of malware transactions, making it difficult to identify and prevent botnet-related threats effectively.
Innovation Solution
A method and apparatus for detecting malware infection by monitoring communications between a local host and external entities, generating dialog warnings for specific transactions indicative of bot infections, and declaring an infection if a combination of warnings meets a predefined threshold within a certain time period, using a weighted event threshold system and a network dialog correlation matrix to output an infection profile.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional IDS/IPS systems are used to detect malware, then the system structure is simple, but the detection precision and ability to predict transaction sequences is insufficient
Solution Approach 1:
The patent segments the malware detection process into distinct transaction types (C2 communication, DDoS activity, data exfiltration, etc.) and models them as separate dialog transactions. Each transaction type is detected and analyzed independently, then integrated into a comprehensive infection profile, improving detection precision without overwhelming system complexity
Solution Approach 2:
The patent introduces a temporal dimension by modeling malware infections as sequences of dialog transactions over time. The system analyzes not just individual events but the ordered sequences and time-windows of transactions, adding a temporal layer to traditional detection that significantly improves precision in identifying botnet behavior patterns
2Reliability
If comprehensive monitoring of all communications is performed, then detection reliability improves, but the loss of time for processing increases
Solution Approach 1:
The patent applies partial action by focusing monitoring efforts on specific dialog transactions indicative of malware (C2 communications, DDoS patterns, etc.) rather than analyzing all network traffic equally. This selective approach maintains high detection reliability for malware while reducing overall processing time by ignoring benign traffic
Solution Approach 2:
The system performs preliminary classification of transactions into malware-indicative categories using predefined models. By pre-establishing what constitutes suspicious behavior patterns and organizing transactions into structured dialog sequences beforehand, the system prepares data for faster analysis and reduces processing time during actual detection operations
3Measurement precision
If the system declares infection based on multiple dialog warnings within a time period, then false positives are reduced, but the complexity of determining transaction sequences increases
Solution Approach 1:
The patent implements a dynamic threshold system where the number of required dialog warnings and the time-window for evaluation can be adjusted based on the specific malware type and infection scenario. This dynamic approach allows the system to adapt to different threat levels and patterns, improving detection accuracy while managing complexity through flexibility rather than rigid rules
Solution Approach 2:
The system creates simplified representations (copies) of complex transaction sequences through standardized dialog warning formats. Each transaction is copied into a uniform structure with defined attributes, making sequence analysis more manageable. The infection profile itself is a simplified copy that captures the essential pattern without requiring analysis of every raw network packet
Data Source
AI summary
In one embodiment, the present invention is a method and apparatus for detecting malware infection. One embodiment of a method for detecting a malware infection at a local host in a network, includes monitoring communications between the local host and one or more entities external to the network, generating a dialog warning if the communications include a transaction indicative of a malware infection, declaring a malware infection if, within a predefined period of time, the dialog warnings includes at least one dialog warning indicating a transaction initiated at the local host and at least one dialog warning indicating an additional transaction indicative of a malware infection, and outputting an infection profile for the local host.


