Script Malware IOC Generation via Behavior and Collection Time Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques are ineffective in generating Indicator of Compromise (IOC) for script-type malware, as they primarily focus on executable binary-type malware and struggle with the variability in activity traces over time, making it difficult to determine effective IOC for script-type malware.
Innovation Solution
A system that acquires behavior information and collection information related to script-type malware, classifies it into groups based on behavior and collection time, detects activity traces, and generates IOC from these classified traces, effectively treating script-type malware as a unified family for detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional IOC generation methods are used for executable binary-type malware, then IOC can be generated based on family characteristics, but these methods are ineffective for script-type malware that lacks clear family information
Solution Approach 1:
The patent creates a unified IOC generation framework that handles both executable binary-type malware and script-type malware using the same classification and extraction mechanisms. The system universally applies behavior analysis and trace extraction to different malware types, making the IOC generation process adaptable to various malware formats while maintaining reliable detection accuracy.
Solution Approach 2:
The patent changes the approach from family-based IOC generation to behavior-based IOC generation. By shifting the fundamental parameter from malware family classification to actual observed behavior traces, the system can effectively generate IOC for script-type malware that previously lacked clear family characteristics, thereby improving both adaptability and reliability.
2Adaptability or versatility
If IOC is generated from activity traces of script-type malware with high variability over time, then detection coverage can be improved, but the variability makes it difficult to determine effective IOC
Solution Approach 1:
The patent performs preliminary classification of behavior traces into essential and non-essential categories before generating IOC. By pre-processing the variable traces and identifying consistent essential behaviors across different time periods, the system can generate reliable IOC that maintain detection coverage while accounting for trace variability.
Solution Approach 2:
The patent extracts only the essential and consistent behavior traces from the variable activity logs, separating them from non-essential variations. This extraction process isolates the core detection-relevant behaviors that remain consistent over time, enabling precise IOC generation despite overall trace variability.
3Adaptability or versatility
If a large number of IOCs are created to cover more malware types, then detection coverage increases, but collation time increases unnecessarily
Solution Approach 1:
The patent extracts only the essential behavior traces that are truly useful for detection, removing non-essential traces that would increase collation time without improving detection coverage. This selective extraction creates a streamlined set of IOC that maintains comprehensive malware detection while minimizing unnecessary collation time.
4Measurement precision
If manual analysis is performed to extract useful traces for IOC generation, then detection accuracy improves, but automation level decreases
Solution Approach 1:
The patent implements an automated system that performs trace classification and IOC generation without requiring manual analysis. The system automatically identifies essential traces, classifies them, and generates IOC through automated processing pipelines, achieving both high trace selection accuracy and full automation for scalable IOC generation.
Data Source
AI summary
A trace information generation device (10) includes an acquisition unit (15a) that acquires behavior information related to a behavior of malware and collection information related to a date and time when the malware is collected, a first classification unit (15c) that classifies the malware into a first group based on the behavior information, a second classification unit (15e) that further classifies the malware classified into the first group into a second group based on the collection information, a detection unit (15b) that detects an activity trace of the malware from the behavior information, and a generation unit (15f) that generates trace information of the malware from the activity trace indicated by the malware classified into the second group.


