Malware Lateral Movement Detection via Packet Criteria Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting malware and other threats in networks are slow, allowing threats to spread and cause significant damage before detection, with an average time of 300 days to detect threats, leading to extensive damage and loss of consumer confidence.

Innovation Solution

A system and method for rapid detection of malware and threats by analyzing packet criteria and using logical models, such as logical trees, to determine threat status and issue alerts, minimizing damage by enabling immediate mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If traditional malware detection methods are used, then threats can be detected, but the detection time is too long (average 300 days) allowing threats to spread widely

Engineering Contradiction:
Improvedetection timeVSAvoidthreat detection reliability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary analysis of network packets by extracting and analyzing packet criteria (source IP, destination IP, ports, protocols) to establish baseline patterns of normal and suspicious traffic. Logical models are pre-configured with indicators of compromise (IOCs) and behavioral patterns that enable early detection of lateral movement activities before full-scale infection occurs, reducing detection time from 300 days to significantly shorter periods

Inventive Principle:
Principle #10Preliminary action

2Speed

If comprehensive network monitoring is implemented to detect threats early, then detection speed improves, but system complexity increases

Engineering Contradiction:
Improvethreat detection speedVSAvoiddetection system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The detection system is segmented into modular components: packet capture modules, packet criteria extraction modules, logical model evaluation modules, and alert generation modules. Each component handles specific aspects of threat detection independently, allowing the system to achieve comprehensive monitoring capability while maintaining manageable complexity through clear separation of concerns and reusable modular units

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Logical models serve as intermediaries between raw packet data and threat detection conclusions. These models contain pre-defined indicators of compromise (IOCs), behavioral patterns, and lateral movement signatures that mediate the analysis process, enabling fast detection without requiring complex real-time decision logic in the monitoring system itself

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If rapid threat detection is achieved through packet analysis, then damage is minimized, but the complexity of analyzing packet criteria increases

Engineering Contradiction:
Improvenetwork damageVSAvoidpacket analysis complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system extracts only the most relevant packet criteria (source IP address, destination IP address, source port, destination port, protocol type) from complete network packets for analysis. By taking out and focusing on these specific critical fields rather than analyzing entire packet contents, the system achieves rapid threat detection and damage minimization while keeping the analysis complexity manageable through selective field extraction

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10965693B2Method and system for detecting movement of malware and other potential threats
Publication Date: 2021.03.30 FENROR7 LTD
  • US10965693B2 patent drawing
  • US10965693B2 patent drawing
  • US10965693B2 patent drawing

AI summary

Methods and systems, including devices, which allow for the rapid detection of malware and other threats, such as malicious intrusions and attacks, are disclosed. These methods and systems, including devices, detect malware and other threats by detecting and analyzing lateral movement of the malware and other threats, once having entered a network, such as an enterprise network.