Remote Malware Detection via Network Delay Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security management systems in network communications, especially in 'bring your own device' environments, face challenges in effectively detecting malware without generating native network traffic and require intensive maintenance for software updates.

Innovation Solution

A remote monitoring system that uses processing circuitry to initiate communication with devices, provide ping messages to determine delay signatures, and compare them to malware traffic signatures stored in a library to identify malware execution without native network traffic generation or software installation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MDMs are used to check for malware in bring your own device environments, then malware detection capability is improved, but maintenance intensity increases due to continuous updates and patches required

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidmaintenance intensity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the malware detection functionality from the device itself and relocates it to a remote server. The server performs all malware detection operations remotely by analyzing device behavior and network traffic patterns, eliminating the need for local antivirus software that requires continuous updates and maintenance on each device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a virtual copy of the device's operational state by monitoring and analyzing network traffic patterns, device behavior metrics, and system responses. This copied data is then analyzed remotely by the server to detect malware without requiring the actual malware scanning software to be installed and maintained on the device.

Inventive Principle:
Principle #26Copying

2Reliability

If traditional antivirus software is installed on every device, then malware detection is improved, but device resource consumption and complexity increase

Engineering Contradiction:
Improvemalware detectionVSAvoidsoftware installation and resource usage
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the computationally intensive malware detection processing from the device and relocates it entirely to a remote server. The device only needs to provide basic telemetry data and network traffic information, while all complex analysis and detection operations are performed remotely, significantly reducing device resource consumption and software complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a remote server as an intermediary between the device and the malware detection process. This intermediary collects device metrics and network traffic data, performs comprehensive malware analysis, and returns results to the device, thereby eliminating the need for heavy antivirus software to be installed and run directly on the device.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If remote monitoring is implemented without native network traffic generation, then device security is improved, but detection capability may be reduced

Engineering Contradiction:
Improvedevice securityVSAvoidmalware detection accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent performs preliminary actions by establishing baseline device behavior patterns and normal network traffic characteristics before malware detection begins. The system pre-configures monitoring parameters and creates reference profiles of legitimate device operations, enabling accurate malware detection through comparison without requiring the device to generate additional network traffic during the actual detection process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical approach of generating active network traffic for detection with a passive monitoring system that analyzes existing device behavior and network patterns. Instead of mechanically probing the device with test packets, the system substitutes this with intelligent analysis of naturally occurring device operations and traffic patterns to detect malware anomalies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10567398B2Method and apparatus for remote malware monitoring
Publication Date: 2020.02.18 JOHNS HOPKINS UNIVERSITY
  • US10567398B2 patent drawing
  • US10567398B2 patent drawing
  • US10567398B2 patent drawing

AI summary

A method executable via operation of configured processing circuitry to identify applications by remote monitoring may include initiating remote communication with a target device through an access point, the access point providing network access to the target device, providing a series of ping messages to the target device via the access point to determine a delay signature of an application running on the target device, comparing the delay signature of the application to a plurality of malware traffic signatures stored in a malware traffic signature library, and determining a matching score between the delay signature of the application and at least some of the malware traffic signatures.