Malware Detection via Event Clustering and Pattern Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware detection techniques face challenges in efficiently identifying infected terminals due to the vast number of malware patterns, leading to prolonged detection times and erroneous false positives, as they treat each communication pattern uniquely and fail to distinguish between malicious and normal communications.

Innovation Solution

A malware detection apparatus that generates event series based on predetermined conditions from communications in a monitoring network, clusters similar events, and extracts common patterns to reduce the number of patterns for comparison, thereby detecting infected terminals more efficiently and accurately.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If patterning of all communications of all pieces of malware is performed, then detection coverage is improved, but detection time increases significantly

Engineering Contradiction:
Improvedetection coverageVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts and removes common events that appear in both malware communications and normal communications from the detection patterns. By taking out these non-discriminative events, the system reduces the number of patterns to be checked while maintaining detection coverage for truly malicious communications.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter of pattern representation from individual communication payloads to clusters of events with similarity thresholds. By grouping similar communications and using representative patterns, the system reduces the total number of patterns while preserving detection effectiveness.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If each communication payload is treated as a unique pattern, then detection precision is improved, but false positives increase

Engineering Contradiction:
Improvedetection precisionVSAvoidfalse positives
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent merges multiple communication patterns into clusters based on event similarity. By combining similar patterns and using representative patterns for detection, the system maintains precision while reducing false positives caused by treating each unique payload as entirely distinct.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts and removes common events that appear in both malware and normal communications from the detection patterns. This extraction of non-discriminative elements eliminates a major source of false positives while preserving detection of truly malicious communications.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If the number of detection patterns is reduced, then detection time is decreased, but detection coverage may be compromised

Engineering Contradiction:
Improvedetection speedVSAvoiddetection coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent creates universal detection patterns that can identify multiple variants of malware through common behavioral characteristics. By focusing on universal patterns rather than specific payload variations, the system achieves both reduced detection time and maintained coverage across diverse malware types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms the detection approach from payload-specific patterns to event-based patterns with similarity thresholds. This parameter change allows a single pattern to cover multiple similar communications, improving detection speed while maintaining coverage through the similarity matching mechanism.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10819717B2Malware infected terminal detecting apparatus, malware infected terminal detecting method, and malware infected terminal detecting program
Publication Date: 2020.10.27 NIPPON TELEGRAPH & TELEPHONE CORP
  • US10819717B2 patent drawing
  • US10819717B2 patent drawing
  • US10819717B2 patent drawing

AI summary

A detecting apparatus generates a collection of events, the collection being formed based on a predetermined condition, from events obtained for each identifier identifying a terminal in a monitoring target network or a piece of malware. The detecting apparatus then extracts, from a cluster formed of collections of events, the collections having a similarity therebetween equal to or larger than a certain similarity, events commonly appearing in the collections of events belonging to the same cluster, and extracts, according to a predetermined condition, the taken out events as a collection of detection purpose events. The detecting apparatus then detects that a malware infected terminal is present in the monitoring target network, if a generated collection of events based on communications in the monitoring target network is determined to match the extracted collection of detection purpose events.