Script Malware IOC Generation via Behavior and Collection Time Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques are ineffective in generating Indicator of Compromise (IOC) for script-type malware, as they primarily focus on executable binary-type malware and struggle with the variability in activity traces over time, making it difficult to determine effective IOC for script-type malware.

Innovation Solution

A system that acquires behavior information and collection information related to script-type malware, classifies it into groups based on behavior and collection time, detects activity traces, and generates IOC from these classified traces, effectively treating script-type malware as a unified family for detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional IOC generation methods are used for executable binary-type malware, then IOC can be generated based on family characteristics, but these methods are ineffective for script-type malware that lacks clear family information

Engineering Contradiction:
ImproveIOC generation capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a unified IOC generation framework that handles both executable binary-type malware and script-type malware using the same classification and extraction mechanisms. The system universally applies behavior analysis and trace extraction to different malware types, making the IOC generation process adaptable to various malware formats while maintaining reliable detection accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the approach from family-based IOC generation to behavior-based IOC generation. By shifting the fundamental parameter from malware family classification to actual observed behavior traces, the system can effectively generate IOC for script-type malware that previously lacked clear family characteristics, thereby improving both adaptability and reliability.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If IOC is generated from activity traces of script-type malware with high variability over time, then detection coverage can be improved, but the variability makes it difficult to determine effective IOC

Engineering Contradiction:
Improvedetection coverageVSAvoidtrace consistency
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary classification of behavior traces into essential and non-essential categories before generating IOC. By pre-processing the variable traces and identifying consistent essential behaviors across different time periods, the system can generate reliable IOC that maintain detection coverage while accounting for trace variability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the essential and consistent behavior traces from the variable activity logs, separating them from non-essential variations. This extraction process isolates the core detection-relevant behaviors that remain consistent over time, enabling precise IOC generation despite overall trace variability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If a large number of IOCs are created to cover more malware types, then detection coverage increases, but collation time increases unnecessarily

Engineering Contradiction:
Improvemalware detection coverageVSAvoidcollation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent extracts only the essential behavior traces that are truly useful for detection, removing non-essential traces that would increase collation time without improving detection coverage. This selective extraction creates a streamlined set of IOC that maintains comprehensive malware detection while minimizing unnecessary collation time.

Inventive Principle:
Principle #2Taking out (Extraction)

4Measurement precision

If manual analysis is performed to extract useful traces for IOC generation, then detection accuracy improves, but automation level decreases

Engineering Contradiction:
Improvetrace selection accuracyVSAvoidIOC generation automation
Core Design Contradiction:
Measurement precisionVSExtent of automation

Solution Approach 1:

The patent implements an automated system that performs trace classification and IOC generation without requiring manual analysis. The system automatically identifies essential traces, classifies them, and generates IOC through automated processing pipelines, achieving both high trace selection accuracy and full automation for scalable IOC generation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250021651A1Generation device, generation method, and generation program
Publication Date: 2025.01.16 NT T INC
  • US20250021651A1 patent drawing
  • US20250021651A1 patent drawing
  • US20250021651A1 patent drawing

AI summary

A trace information generation device (10) includes an acquisition unit (15a) that acquires behavior information related to a behavior of malware and collection information related to a date and time when the malware is collected, a first classification unit (15c) that classifies the malware into a first group based on the behavior information, a second classification unit (15e) that further classifies the malware classified into the first group into a second group based on the collection information, a detection unit (15b) that detects an activity trace of the malware from the behavior information, and a generation unit (15f) that generates trace information of the malware from the activity trace indicated by the malware classified into the second group.