Malware Inspection via OpenFlow Packet Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques face challenges in safely monitoring and collecting cyber threat intelligence from personal computers infected with malware controlled by a command and control server located outside the system.

Innovation Solution

A malware inspection apparatus and method utilizing an OpenFlow switch that redirects packets from infected terminals to a mimic network system, allowing for safe monitoring and intelligence collection by isolating the malware-infected terminals within a honey network system, thereby preventing attacks from reaching other devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If malware-infected terminals are monitored directly in the original system, then cyber threat intelligence can be collected, but the system security is compromised and attacks may spread to other devices

Engineering Contradiction:
Improvecyber threat intelligence collectionVSAvoidsystem security
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The network is segmented into multiple isolation layers: the original system network, the mimic network system with infected terminals, and the inspection apparatus network. This segmentation allows CTI collection from infected terminals while preventing attack propagation to the original system through physical and logical network separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The inspection apparatus acts as an intermediary between the mimic network system and the original system. It monitors and analyzes malicious traffic from infected terminals in the mimic network while blocking direct communication with the original system, thus enabling secure CTI collection without compromising system security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If infected terminals are isolated in a mimic network system, then system security is protected, but monitoring and intelligence collection become more complex

Engineering Contradiction:
Improvesystem securityVSAvoidnetwork system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A mimic network system is created as a copy of the original system, replicating its structure, protocols, and services. This copying approach enables realistic malware behavior observation while maintaining isolation, and the replicated environment can be safely managed without affecting the original system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The inspection apparatus performs multiple functions simultaneously: it monitors network traffic, analyzes malicious behavior, collects cyber threat intelligence, and maintains isolation between networks. This multi-functionality reduces the need for separate dedicated systems for each task, thereby managing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If packet destination addresses are changed to redirect traffic, then infected terminals can be redirected to the mimic network, but network address management becomes more complex

Engineering Contradiction:
Improveattack preventionVSAvoidaddress management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The inspection apparatus serves as an address translation intermediary, intercepting packets from infected terminals and modifying their destination addresses to route traffic to the mimic network system. This centralized address management at the inspection apparatus simplifies the complexity compared to distributed address management across multiple network devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11418537B2Malware inspection apparatus and malware inspection method
Publication Date: 2022.08.16 FUJITSU LTD
  • US11418537B2 patent drawing
  • US11418537B2 patent drawing
  • US11418537B2 patent drawing

AI summary

A malware inspection apparatus includes one or more memories, and one or more processors configured to, when a first terminal belonging to a first system is infected with malware, in response to receiving, from the first terminal, a first packet destined for a second terminal belonging to the first system, change a destination address of the first packet to an address of a third terminal belonging to a second system, and send the changed first packet to the third terminal.