NIC Malware Detection via Multi-Channel Pattern Merging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network interface controller (NIC) systems are vulnerable to advanced malware that splits transmission packets across multiple session channels, evading detection by antivirus software limited to single session channel processing.
Innovation Solution
A protection method and computer system that processes microbatching operations across multiple session channels to generate session-specific NIC patterns, merging them into an application-specific pattern at the application layer to identify and counter malware attacks, using a cluster controller and machine learning models for pattern recombination and prediction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If antivirus software processes detection in single session channel only, then the device complexity is reduced, but the malware detection capability deteriorates because advanced malware can divide transmission packets into sub-packets across different session channels to evade detection
Solution Approach 1:
The patent merges detection capabilities across multiple session channels by creating a unified detection mechanism that aggregates packets from different session channels. The system combines session-specific NIC patterns from multiple channels to generate an application-specific NIC pattern, enabling comprehensive malware detection across all channels while maintaining manageable complexity through systematic integration.
Solution Approach 2:
The detection system is designed to handle multiple session channels simultaneously with a single unified detection mechanism. The application-specific NIC pattern serves as a universal detection signature that can identify malware regardless of which session channel the malicious packets traverse, making the detection system multi-functional across different communication channels.
2Measurement precision
If antivirus software updates virus pattern information timely, then the malware detection accuracy is improved, but the loss of time for system updates increases
Solution Approach 1:
The system performs preliminary pattern recombination operations to generate application-specific NIC patterns in advance, before actual malware detection is needed. By pre-processing and merging session-specific patterns into comprehensive application-level patterns, the system prepares detection capabilities proactively, reducing the need for frequent urgent updates and minimizing update-related downtime.
Data Source
AI summary
A protection method, which releases an attack of a malware to a network interface controller (NIC) system, includes processing a microbatching operation in a plurality of session channels at at least an operational period according to at least one input information, to generate a plurality of session-specific NIC patterns of the plurality of session channels; and merging the plurality of session-specific NIC patterns to generate an application-specific NIC pattern at an application layer, so as to dispose a script information corresponding to the application-specific NIC pattern in the NICs for releasing the attack of the malware, wherein the microbatching operation is processed to generate a plurality of independent subset-specific NIC pattern in each session channel, so as to generate the session-specific NIC pattern corresponding to each session channel.


