Malware Lateral Movement Detection via Packet Criteria Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting malware and other threats in networks are slow, allowing threats to spread and cause significant damage before detection, with an average time of 300 days to detect threats, leading to extensive damage and loss of consumer confidence.
Innovation Solution
A system and method for rapid detection of malware and threats by analyzing packet criteria and using logical models, such as logical trees, to determine threat status and issue alerts, minimizing damage by enabling immediate mitigation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If traditional malware detection methods are used, then threats can be detected, but the detection time is too long (average 300 days) allowing threats to spread widely
Solution Approach 1:
The system performs preliminary analysis of network packets by extracting and analyzing packet criteria (source IP, destination IP, ports, protocols) to establish baseline patterns of normal and suspicious traffic. Logical models are pre-configured with indicators of compromise (IOCs) and behavioral patterns that enable early detection of lateral movement activities before full-scale infection occurs, reducing detection time from 300 days to significantly shorter periods
2Speed
If comprehensive network monitoring is implemented to detect threats early, then detection speed improves, but system complexity increases
Solution Approach 1:
The detection system is segmented into modular components: packet capture modules, packet criteria extraction modules, logical model evaluation modules, and alert generation modules. Each component handles specific aspects of threat detection independently, allowing the system to achieve comprehensive monitoring capability while maintaining manageable complexity through clear separation of concerns and reusable modular units
Solution Approach 2:
Logical models serve as intermediaries between raw packet data and threat detection conclusions. These models contain pre-defined indicators of compromise (IOCs), behavioral patterns, and lateral movement signatures that mediate the analysis process, enabling fast detection without requiring complex real-time decision logic in the monitoring system itself
3Object-affected harmful factors
If rapid threat detection is achieved through packet analysis, then damage is minimized, but the complexity of analyzing packet criteria increases
Solution Approach 1:
The system extracts only the most relevant packet criteria (source IP address, destination IP address, source port, destination port, protocol type) from complete network packets for analysis. By taking out and focusing on these specific critical fields rather than analyzing entire packet contents, the system achieves rapid threat detection and damage minimization while keeping the analysis complexity manageable through selective field extraction
Data Source
AI summary
Methods and systems, including devices, which allow for the rapid detection of malware and other threats, such as malicious intrusions and attacks, are disclosed. These methods and systems, including devices, detect malware and other threats by detecting and analyzing lateral movement of the malware and other threats, once having entered a network, such as an enterprise network.


