Remote Malware Detection via Network Delay Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security management systems in network communications, especially in 'bring your own device' environments, face challenges in effectively detecting malware without generating native network traffic and require intensive maintenance for software updates.
Innovation Solution
A remote monitoring system that uses processing circuitry to initiate communication with devices, provide ping messages to determine delay signatures, and compare them to malware traffic signatures stored in a library to identify malware execution without native network traffic generation or software installation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MDMs are used to check for malware in bring your own device environments, then malware detection capability is improved, but maintenance intensity increases due to continuous updates and patches required
Solution Approach 1:
The patent extracts the malware detection functionality from the device itself and relocates it to a remote server. The server performs all malware detection operations remotely by analyzing device behavior and network traffic patterns, eliminating the need for local antivirus software that requires continuous updates and maintenance on each device.
Solution Approach 2:
The patent creates a virtual copy of the device's operational state by monitoring and analyzing network traffic patterns, device behavior metrics, and system responses. This copied data is then analyzed remotely by the server to detect malware without requiring the actual malware scanning software to be installed and maintained on the device.
2Reliability
If traditional antivirus software is installed on every device, then malware detection is improved, but device resource consumption and complexity increase
Solution Approach 1:
The patent extracts the computationally intensive malware detection processing from the device and relocates it entirely to a remote server. The device only needs to provide basic telemetry data and network traffic information, while all complex analysis and detection operations are performed remotely, significantly reducing device resource consumption and software complexity.
Solution Approach 2:
The patent introduces a remote server as an intermediary between the device and the malware detection process. This intermediary collects device metrics and network traffic data, performs comprehensive malware analysis, and returns results to the device, thereby eliminating the need for heavy antivirus software to be installed and run directly on the device.
3Object-affected harmful factors
If remote monitoring is implemented without native network traffic generation, then device security is improved, but detection capability may be reduced
Solution Approach 1:
The patent performs preliminary actions by establishing baseline device behavior patterns and normal network traffic characteristics before malware detection begins. The system pre-configures monitoring parameters and creates reference profiles of legitimate device operations, enabling accurate malware detection through comparison without requiring the device to generate additional network traffic during the actual detection process.
Solution Approach 2:
The patent replaces the mechanical approach of generating active network traffic for detection with a passive monitoring system that analyzes existing device behavior and network patterns. Instead of mechanically probing the device with test packets, the system substitutes this with intelligent analysis of naturally occurring device operations and traffic patterns to detect malware anomalies.
Data Source
AI summary
A method executable via operation of configured processing circuitry to identify applications by remote monitoring may include initiating remote communication with a target device through an access point, the access point providing network access to the target device, providing a series of ping messages to the target device via the access point to determine a delay signature of an application running on the target device, comparing the delay signature of the application to a plurality of malware traffic signatures stored in a malware traffic signature library, and determining a matching score between the delay signature of the application and at least some of the malware traffic signatures.


