Network Node Persistence Detection for Malware Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware detection techniques are imperfect and dependent on deployment location, leading to a constant arms race between malware writers and security measures, with a need for improved detection of persistent network-using malware.

Innovation Solution

A method and device that monitor network node connectivity sessions, determine intra-session and inter-session persistence ratios, and utilize signaling information to identify persistent malware by analyzing communication patterns and network activity, reducing false positives and improving detection performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing malware detection techniques are used, then detection can be performed, but detection performance is imperfect and false positives occur

Engineering Contradiction:
Improvedetection performanceVSAvoidfalse positives
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the detection process into multiple independent analysis dimensions: session persistence analysis (dividing into intra-session and inter-session components), communication flow analysis, and temporal pattern analysis. Each segment analyzes specific aspects of network behavior independently, then combines results to achieve more accurate detection with reduced false positives.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic threshold adjustment based on observed network behavior patterns. Instead of using fixed thresholds, the system adapts thresholds based on historical data and learned patterns of legitimate versus malicious behavior, improving detection accuracy while reducing false positives through dynamic adaptation.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If signature-based detection methods are used, then specific malware can be detected, but new malware variants evade detection due to the arms race between malware writers and security measures

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidability to detect new malware variants
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary analysis of network session patterns and establishes baseline behavior profiles before malware execution. By pre-characterizing legitimate communication patterns, the system can detect deviations indicating new malware variants without requiring pre-existing signatures, enabling detection of previously unseen threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transitions from static signature-based detection to dynamic parameter-based detection by analyzing multiple variables including session duration, communication frequency, data transfer patterns, and temporal distribution. This multi-parameter approach allows the system to detect new malware variants by identifying anomalous parameter combinations rather than relying on fixed signatures.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If host-based detection techniques are used, then malware on specific devices can be detected, but deployment flexibility is limited compared to network-based approaches

Engineering Contradiction:
Improvedevice-level detection accuracyVSAvoiddeployment flexibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent designs a detection system that functions universally across multiple deployment scenarios. The same core analysis engine can be deployed at the host level for device-specific detection, at the network level for broader monitoring, or in hybrid configurations. This multi-functionality provides both precise device-level detection and flexible deployment options.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3404949B1Detection of persistency of a network node
Publication Date: 2019.09.25 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3404949B1 patent drawingFigure 1~2
  • EP3404949B1 patent drawingFigure 3
  • EP3404949B1 patent drawingFigure 4

AI summary

The invention relates to a method, device and computer program for detecting persistency of a first network node. The method comprises monitoring, during a specified observation period, whether the first network node has established a connection to a second network node; determining a total number of sessions of connectivity occurring between the first network node and the second network node during said observation period; determining, from the total number of sessions, sessions comprising at least one communication flow between the first network node and the second network node; dividing at least one session into a number of sub-sessions; determining, for the at least one session, the number of sub-sessions comprising at least one communication flow between the first network node and the second network node; and determining intra-session persistence of the first network node for the session on the basis of the number of sub-sessions and said number of sub-sessions.