Malware Detection via Dialog Correlation Matrix

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems (IDSs) and intrusion prevention systems (IPSs) fail to accurately detect botnet infections and predict the order and time-window of malware transactions, making it difficult to identify and prevent botnet-related threats effectively.

Innovation Solution

A method and apparatus for detecting malware infection by monitoring communications between a local host and external entities, generating dialog warnings for specific transactions indicative of bot infections, and declaring an infection if a combination of warnings meets a predefined threshold within a certain time period, using a weighted event threshold system and a network dialog correlation matrix to output an infection profile.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional IDS/IPS systems are used to detect malware, then the system structure is simple, but the detection precision and ability to predict transaction sequences is insufficient

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the malware detection process into distinct transaction types (C2 communication, DDoS activity, data exfiltration, etc.) and models them as separate dialog transactions. Each transaction type is detected and analyzed independently, then integrated into a comprehensive infection profile, improving detection precision without overwhelming system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a temporal dimension by modeling malware infections as sequences of dialog transactions over time. The system analyzes not just individual events but the ordered sequences and time-windows of transactions, adding a temporal layer to traditional detection that significantly improves precision in identifying botnet behavior patterns

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive monitoring of all communications is performed, then detection reliability improves, but the loss of time for processing increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing monitoring efforts on specific dialog transactions indicative of malware (C2 communications, DDoS patterns, etc.) rather than analyzing all network traffic equally. This selective approach maintains high detection reliability for malware while reducing overall processing time by ignoring benign traffic

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary classification of transactions into malware-indicative categories using predefined models. By pre-establishing what constitutes suspicious behavior patterns and organizing transactions into structured dialog sequences beforehand, the system prepares data for faster analysis and reduces processing time during actual detection operations

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If the system declares infection based on multiple dialog warnings within a time period, then false positives are reduced, but the complexity of determining transaction sequences increases

Engineering Contradiction:
Improveinfection detection accuracyVSAvoidsequence analysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a dynamic threshold system where the number of required dialog warnings and the time-window for evaluation can be adjusted based on the specific malware type and infection scenario. This dynamic approach allows the system to adapt to different threat levels and patterns, improving detection accuracy while managing complexity through flexibility rather than rigid rules

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system creates simplified representations (copies) of complex transaction sequences through standardized dialog warning formats. Each transaction is copied into a uniform structure with defined attributes, making sequence analysis more manageable. The infection profile itself is a simplified copy that captures the essential pattern without requiring analysis of every raw network packet

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10270803B2Method and apparatus for detecting malware infection
Publication Date: 2019.04.23 CRIBL INC
  • US10270803B2 patent drawing
  • US10270803B2 patent drawing
  • US10270803B2 patent drawing

AI summary

In one embodiment, the present invention is a method and apparatus for detecting malware infection. One embodiment of a method for detecting a malware infection at a local host in a network, includes monitoring communications between the local host and one or more entities external to the network, generating a dialog warning if the communications include a transaction indicative of a malware infection, declaring a malware infection if, within a predefined period of time, the dialog warnings includes at least one dialog warning indicating a transaction initiated at the local host and at least one dialog warning indicating an additional transaction indicative of a malware infection, and outputting an infection profile for the local host.