Network Anomaly Detection via User Communication Overlap Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting mobile malware and spam in networks are limited, as they often rely on host device protections that are ineffective against new strains, and user feedback-based techniques fail to identify entire malware campaigns, which can span both SMS and internet data, with attackers using premium short code services and multiple command and control domains to evade detection.

Innovation Solution

A network-level approach that detects communication anomalies by identifying overlaps and similarities between entities such as domain names, IP addresses, and phone numbers, using a clustering algorithm and similarity metrics to identify suspicious patterns, and applying additional criteria like reputation and operating system entropy to determine if communication is anomalous.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host-based protections (anti-virus software) are deployed on mobile devices, then protection against known malware is improved, but effectiveness against new unseen strains of malware deteriorates

Engineering Contradiction:
Improveprotection effectivenessVSAvoidability to detect new malware strains
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from host-based detection to network-level detection by analyzing communication patterns between mobile devices and external entities (domains, IP addresses, phone numbers). This dimensional shift enables detection of malware campaigns based on their network behavior rather than relying on host-based signatures, thereby improving adaptability to new malware strains while maintaining reliability through comprehensive network-wide analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system performs preliminary monitoring and data collection during a training period to establish baseline communication patterns and build reputation databases for domains, IP addresses, and phone numbers. This preliminary action enables the system to detect anomalies in real-time without requiring real-time analysis of every communication, improving both detection capability and system responsiveness to new threats.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If user feedback-based techniques are used to detect spam, then detection of reported spam is improved, but ability to identify entire malware campaigns deteriorates

Engineering Contradiction:
Improvespam detection accuracyVSAvoidcampaign identification capability
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple data sources including user feedback, automated reputation analysis, communication pattern analysis, and network-wide monitoring into a unified detection system. By combining these approaches, the system maintains high precision for detecting reported spam while simultaneously gaining the capability to identify entire malware campaigns through pattern recognition across multiple entities and communication channels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where detection results from individual spam reports are fed back into the reputation database and pattern analysis system. This feedback loop allows the system to learn from individual detections and improve overall campaign identification, transforming isolated precision measurements into comprehensive campaign-level insights.

Inventive Principle:
Principle #23Feedback

3Reliability

If domain blacklists are maintained to identify infected users, then detection of known command and control channels is improved, but ability to identify malware campaigns beforehand deteriorates

Engineering Contradiction:
Improveinfection detectionVSAvoidcampaign identification timing
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary monitoring and reputation assessment during a training period before malware campaigns fully deploy. By proactively analyzing communication patterns and building reputation databases in advance, the system can identify potential command and control channels before they are widely used, enabling early campaign identification rather than reactive detection after infections occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent expands detection from single-domain blacklisting to multi-dimensional analysis including domains, IP addresses, phone numbers, and short codes simultaneously. This dimensional expansion allows the system to identify malware campaigns through patterns across multiple entity types, providing earlier detection capability while maintaining reliable identification of known command and control channels.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Adaptability or versatility

If network-level monitoring is implemented to detect malware campaigns, then campaign identification capability is improved, but system complexity and computational requirements worsen

Engineering Contradiction:
Improvecampaign detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network monitoring system into distinct functional modules: data collection from multiple sources, reputation database management, communication pattern analysis, clustering algorithms for entity grouping, and anomaly detection. This segmentation reduces system complexity by making each component independent and manageable while maintaining comprehensive campaign detection capability through their coordinated operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary components including reputation databases that store pre-computed entity ratings and clustering algorithms that group related entities before detailed analysis. These intermediaries reduce computational complexity by pre-processing and organizing data, allowing the system to handle large-scale network monitoring while maintaining adaptability for campaign detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9641545B2Methods, systems, and computer program products for detecting communication anomalies in a network based on overlap between sets of users communicating with entities in the network
Publication Date: 2017.05.02 AT&T INTELLECTUAL PROPERTY I L P
  • US9641545B2 patent drawing
  • US9641545B2 patent drawing
  • US9641545B2 patent drawing

AI summary

Anomalies are detected in a network by detecting communication between a plurality of entities and a set of users in the network, determining an overlap between subsets of the set of users that the entities comprising the plurality of entities communicated with, respectively, and determining whether the communication between the plurality of entities and the set of users is anomalous based on the overlap.