Malware Detection via Event Clustering and Pattern Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional malware detection techniques face challenges in efficiently identifying infected terminals due to the vast number of malware patterns, leading to prolonged detection times and erroneous false positives, as they treat each communication pattern uniquely and fail to distinguish between malicious and normal communications.
Innovation Solution
A malware detection apparatus that generates event series based on predetermined conditions from communications in a monitoring network, clusters similar events, and extracts common patterns to reduce the number of patterns for comparison, thereby detecting infected terminals more efficiently and accurately.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If patterning of all communications of all pieces of malware is performed, then detection coverage is improved, but detection time increases significantly
Solution Approach 1:
The patent extracts and removes common events that appear in both malware communications and normal communications from the detection patterns. By taking out these non-discriminative events, the system reduces the number of patterns to be checked while maintaining detection coverage for truly malicious communications.
Solution Approach 2:
The patent changes the parameter of pattern representation from individual communication payloads to clusters of events with similarity thresholds. By grouping similar communications and using representative patterns, the system reduces the total number of patterns while preserving detection effectiveness.
2Measurement precision
If each communication payload is treated as a unique pattern, then detection precision is improved, but false positives increase
Solution Approach 1:
The patent merges multiple communication patterns into clusters based on event similarity. By combining similar patterns and using representative patterns for detection, the system maintains precision while reducing false positives caused by treating each unique payload as entirely distinct.
Solution Approach 2:
The patent extracts and removes common events that appear in both malware and normal communications from the detection patterns. This extraction of non-discriminative elements eliminates a major source of false positives while preserving detection of truly malicious communications.
3Productivity
If the number of detection patterns is reduced, then detection time is decreased, but detection coverage may be compromised
Solution Approach 1:
The patent creates universal detection patterns that can identify multiple variants of malware through common behavioral characteristics. By focusing on universal patterns rather than specific payload variations, the system achieves both reduced detection time and maintained coverage across diverse malware types.
Solution Approach 2:
The patent transforms the detection approach from payload-specific patterns to event-based patterns with similarity thresholds. This parameter change allows a single pattern to cover multiple similar communications, improving detection speed while maintaining coverage through the similarity matching mechanism.
Data Source
AI summary
A detecting apparatus generates a collection of events, the collection being formed based on a predetermined condition, from events obtained for each identifier identifying a terminal in a monitoring target network or a piece of malware. The detecting apparatus then extracts, from a cluster formed of collections of events, the collections having a similarity therebetween equal to or larger than a certain similarity, events commonly appearing in the collections of events belonging to the same cluster, and extracts, according to a predetermined condition, the taken out events as a collection of detection purpose events. The detecting apparatus then detects that a malware infected terminal is present in the monitoring target network, if a generated collection of events based on communications in the monitoring target network is determined to match the extracted collection of detection purpose events.


