OS Start Event Detection via Passive Network Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing behavioral analytics systems face challenges in detecting operating system start events and malware infections due to resource consumption and network bandwidth issues when actively monitoring and reporting device behavior, which can alter the behavior of devices and networks.
Innovation Solution
A device in a network passively tracks changes in source port or address identifiers in network traffic to detect operating system start events and provides this data to a machine learning-based malware detector, allowing for mitigation actions without explicit reporting from hosts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active monitoring and reporting of device behavior is implemented, then detection accuracy of OS start events and malware infections is improved, but resource consumption and network bandwidth usage increase
Solution Approach 1:
The patent enables devices to self-report OS start events and behavioral changes autonomously without requiring continuous external monitoring. Each device monitors its own operational state (OS start events, application launches) and automatically generates reports when specific events occur, eliminating the need for resource-intensive continuous external monitoring while maintaining high detection accuracy
Solution Approach 2:
Instead of continuous monitoring, the system implements event-driven periodic reporting where devices report their state only when specific events occur (OS start, application launch, behavioral changes). This transforms continuous resource consumption into discrete periodic actions, significantly reducing overall resource usage and network bandwidth consumption while preserving detection capability
2Measurement precision
If active monitoring and reporting of device behavior is implemented, then detection accuracy of OS start events and malware infections is improved, but network bandwidth consumption increases
Solution Approach 1:
Devices autonomously monitor and report only their own behavioral events without requiring external probing or continuous communication. This self-service approach minimizes network traffic to essential event reports only, eliminating bandwidth-consuming continuous monitoring while maintaining accurate detection of OS start events and malware indicators
Solution Approach 2:
The system extracts and reports only the most critical behavioral events (OS start events, application launches, significant behavioral changes) rather than transmitting continuous streams of all device activities. This selective extraction of essential information maintains detection accuracy while dramatically reducing network bandwidth consumption by filtering out redundant data
3Loss of information
If monitoring agents are executed on host devices, then information about device behavior is captured, but host resources are consumed
Solution Approach 1:
The system leverages existing device components (operating system event logs, application manifests, built-in monitoring capabilities) to capture behavioral information without introducing external monitoring agents. Devices use their own internal resources to self-monitor and self-report, eliminating the need for additional agent software that would consume host CPU, memory, and processing resources
Data Source
AI summary
In one embodiment, a device in a network tracks traffic features indicated by header information of packets of an encrypted traffic flow over time. The encrypted traffic flow is associated with a particular host in the network. The device detects an operating system start event based on the traffic features and provides data regarding the detected operating system start event as input to a machine learning-based malware detector to determine whether the particular host with which the encrypted traffic flow is associated is infected with malware. The device causes performance of a mitigation action in the network when the malware detector determines that the particular host is infected with malware.


