Network Maliciousness Profiling via Aggregate Signal Spectral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures, such as host reputation systems and blacklists, are ineffective due to the dynamic nature of IP addresses, leading to timeliness and accuracy issues in detecting and mitigating malicious activities, and face scalability challenges with large numbers of IP addresses.

Innovation Solution

A method and system for rating malicious network activity by aggregating IP addresses, measuring malicious traffic, generating aggregate signals, categorizing them, assigning intensity, duration, and frequency features, and performing spectral analysis to create maliciousness profiles, allowing for comparison of network behavior across different networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If host reputation systems and blacklists are used to detect malicious activities, then the ability to identify malicious IP addresses is improved, but the timeliness and accuracy deteriorate due to the dynamic nature of IP addresses

Engineering Contradiction:
Improveaccuracy of malicious activity detectionVSAvoidtimeliness of detection
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent combines multiple IP addresses into aggregate signals representing network-level behavior patterns. By merging individual IP addresses into groups (aggregates) and analyzing their collective behavior over time, the system maintains detection accuracy while reducing the impact of individual IP address dynamics, thus resolving the contradiction between detection accuracy and timeliness.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system dynamically adapts to changing network conditions by continuously monitoring and updating aggregate signals. It uses time-varying analysis to capture evolving malicious behavior patterns, allowing the system to remain timely and accurate despite the dynamic nature of IP addresses and malicious activities.

Inventive Principle:
Principle #15Dynamics

2Quantity of substance

If large numbers of IP addresses are monitored individually, then the coverage of malicious activity detection is improved, but scalability issues arise

Engineering Contradiction:
Improvenumber of monitored IP addressesVSAvoidscalability of monitoring system
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent merges large numbers of individual IP address monitoring tasks into aggregated network-level analysis. By grouping IP addresses into aggregates and analyzing their collective behavior, the system achieves comprehensive coverage of malicious activities while significantly reducing computational complexity and improving scalability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system segments the monitoring task from individual IP addresses to network aggregates. This segmentation allows the system to handle large numbers of IP addresses by processing them in manageable groups, thereby improving scalability while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If filtering and blocking policies are implemented at application or network layer, then the impact of malicious threats is minimized, but the effectiveness is reduced due to reliance on reactive blacklists

Engineering Contradiction:
Improveimpact of malicious threatsVSAvoideffectiveness of filtering policies
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system performs preliminary analysis of network-level behavior patterns to identify potential malicious activities before they manifest as individual IP address threats. By detecting aggregate behavioral anomalies in advance, the system enables proactive filtering and blocking policies that are more effective than reactive blacklist-based approaches.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms that continuously monitor network behavior and update detection models. This feedback loop improves the reliability of filtering policies by adapting to evolving threat patterns, making the system more effective than static blacklist-based approaches.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10038703B2Rating network security posture and comparing network maliciousness
Publication Date: 2018.07.31 THE RGT UNIV OF MICHIGAN
  • US10038703B2 patent drawing
  • US10038703B2 patent drawing
  • US10038703B2 patent drawing

AI summary

Embodiments are disclosed for profiling network-level malicious activity. Profiling embodiments include observing malicious activity, representing such activity in accordance with a set of representative features, capturing temporal evolution of this malicious behavior and its dynamics, and using this temporal evolution to reveal key risk related properties of these networks. Embodiments are further disclosed addressing the connectedness of various networks and similarity in network-level maliciousness. Embodiments directed to similarity analyses include focusing on the notion of similarity—a quantitative measure of the extent to which the dynamic evolutions of malicious activities from two networks are alike, and mapping this behavioral similarity to their similarity in certain spatial features, which includes their relative proximity to each other and may be used to help predict the future maliciousness of a particular network. The embodiments described may be applicable to various network aggregation levels.