OS Start Event Detection via Passive Network Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing behavioral analytics systems face challenges in detecting operating system start events and malware infections due to resource consumption and network bandwidth issues when actively monitoring and reporting device behavior, which can alter the behavior of devices and networks.

Innovation Solution

A device in a network passively tracks changes in source port or address identifiers in network traffic to detect operating system start events and provides this data to a machine learning-based malware detector, allowing for mitigation actions without explicit reporting from hosts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active monitoring and reporting of device behavior is implemented, then detection accuracy of OS start events and malware infections is improved, but resource consumption and network bandwidth usage increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent enables devices to self-report OS start events and behavioral changes autonomously without requiring continuous external monitoring. Each device monitors its own operational state (OS start events, application launches) and automatically generates reports when specific events occur, eliminating the need for resource-intensive continuous external monitoring while maintaining high detection accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of continuous monitoring, the system implements event-driven periodic reporting where devices report their state only when specific events occur (OS start, application launch, behavioral changes). This transforms continuous resource consumption into discrete periodic actions, significantly reducing overall resource usage and network bandwidth consumption while preserving detection capability

Inventive Principle:
Principle #19Periodic action

2Measurement precision

If active monitoring and reporting of device behavior is implemented, then detection accuracy of OS start events and malware infections is improved, but network bandwidth consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork bandwidth
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

Devices autonomously monitor and report only their own behavioral events without requiring external probing or continuous communication. This self-service approach minimizes network traffic to essential event reports only, eliminating bandwidth-consuming continuous monitoring while maintaining accurate detection of OS start events and malware indicators

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system extracts and reports only the most critical behavioral events (OS start events, application launches, significant behavioral changes) rather than transmitting continuous streams of all device activities. This selective extraction of essential information maintains detection accuracy while dramatically reducing network bandwidth consumption by filtering out redundant data

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of information

If monitoring agents are executed on host devices, then information about device behavior is captured, but host resources are consumed

Engineering Contradiction:
Improveinformation captureVSAvoidhost resources
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The system leverages existing device components (operating system event logs, application manifests, built-in monitoring capabilities) to capture behavioral information without introducing external monitoring agents. Devices use their own internal resources to self-monitor and self-report, eliminating the need for additional agent software that would consume host CPU, memory, and processing resources

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11748477B2OS start event detection, OS fingerprinting, and device tracking using enhanced data features
Publication Date: 2023.09.05 CISCO TECHNOLOGY INC
  • US11748477B2 patent drawing
  • US11748477B2 patent drawing
  • US11748477B2 patent drawing

AI summary

In one embodiment, a device in a network tracks traffic features indicated by header information of packets of an encrypted traffic flow over time. The encrypted traffic flow is associated with a particular host in the network. The device detects an operating system start event based on the traffic features and provides data regarding the detected operating system start event as input to a machine learning-based malware detector to determine whether the particular host with which the encrypted traffic flow is associated is infected with malware. The device causes performance of a mitigation action in the network when the malware detector determines that the particular host is infected with malware.