NIC Malware Detection via Multi-Channel Pattern Merging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network interface controller (NIC) systems are vulnerable to advanced malware that splits transmission packets across multiple session channels, evading detection by antivirus software limited to single session channel processing.

Innovation Solution

A protection method and computer system that processes microbatching operations across multiple session channels to generate session-specific NIC patterns, merging them into an application-specific pattern at the application layer to identify and counter malware attacks, using a cluster controller and machine learning models for pattern recombination and prediction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If antivirus software processes detection in single session channel only, then the device complexity is reduced, but the malware detection capability deteriorates because advanced malware can divide transmission packets into sub-packets across different session channels to evade detection

Engineering Contradiction:
Improvedetection system complexityVSAvoidmalware detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges detection capabilities across multiple session channels by creating a unified detection mechanism that aggregates packets from different session channels. The system combines session-specific NIC patterns from multiple channels to generate an application-specific NIC pattern, enabling comprehensive malware detection across all channels while maintaining manageable complexity through systematic integration.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The detection system is designed to handle multiple session channels simultaneously with a single unified detection mechanism. The application-specific NIC pattern serves as a universal detection signature that can identify malware regardless of which session channel the malicious packets traverse, making the detection system multi-functional across different communication channels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If antivirus software updates virus pattern information timely, then the malware detection accuracy is improved, but the loss of time for system updates increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidsystem update time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary pattern recombination operations to generate application-specific NIC patterns in advance, before actual malware detection is needed. By pre-processing and merging session-specific patterns into comprehensive application-level patterns, the system prepares detection capabilities proactively, reducing the need for frequent urgent updates and minimizing update-related downtime.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10079840B2Protection method and computer system of releasing malware attacks for network interface controller system
Publication Date: 2018.09.18 WISTRON CORP
  • US10079840B2 patent drawing
  • US10079840B2 patent drawing
  • US10079840B2 patent drawing

AI summary

A protection method, which releases an attack of a malware to a network interface controller (NIC) system, includes processing a microbatching operation in a plurality of session channels at at least an operational period according to at least one input information, to generate a plurality of session-specific NIC patterns of the plurality of session channels; and merging the plurality of session-specific NIC patterns to generate an application-specific NIC pattern at an application layer, so as to dispose a script information corresponding to the application-specific NIC pattern in the NICs for releasing the attack of the malware, wherein the microbatching operation is processed to generate a plurality of independent subset-specific NIC pattern in each session channel, so as to generate the session-specific NIC pattern corresponding to each session channel.