Spam Honeypot Malware Detection via Feature Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current spam and malware detection systems in computing and communications systems lack effective cross-over mechanisms, with spam honeypots primarily focusing on spam detection and ignoring malware, leading to inefficient protection against malware infections and false positive results.

Innovation Solution

Establishing a decoy email system (spam honeypot) to receive illegitimate emails, filtering out non-malware emails, extracting features from potential malware emails, ranking them for threat indicators, and distributing suspicious parameters to security systems to identify and protect user computing systems from malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If spam honeypots are used to receive large numbers of emails, then the volume of malware-containing emails received increases, but the detection rate of malware in real email systems remains low because the data is not being utilized

Engineering Contradiction:
Improvevolume of malware-containing emails receivedVSAvoiddetection rate of malware in real email systems
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent implements feedback by analyzing malware-containing emails received at the spam honeypot and distributing identified malware indicators back to real email systems. This closed-loop feedback mechanism enables real systems to learn from honeypot data and improve their detection rates continuously

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The spam honeypot acts as an intermediary system that receives malware emails on behalf of real email systems, allowing malware analysis without exposing actual users. The honeypot mediates between malware sources and real email systems, extracting valuable detection data while protecting end users

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all emails at the spam honeypot are analyzed for malware, then the detection capability improves, but the processing time and computational resources increase significantly

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidprocessing time for email analysis
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the malware-containing subset of emails from the total honeypot email volume for detailed analysis. By taking out and focusing only on suspicious emails that contain malware indicators, the system achieves high detection capability while minimizing processing time and resource consumption

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of analyzing all honeypot emails equally, the system applies partial action by concentrating analysis resources on the small proportion of emails that actually contain malware. This selective approach avoids excessive processing of benign spam while maintaining high detection effectiveness

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If spam honeypot data is used to improve malware detection, then false positive results may increase, but the overall protection against malware infections improves

Engineering Contradiction:
Improveprotection against malware infectionsVSAvoidfalse positive rate in malware detection
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The feedback mechanism includes validation steps where malware indicators identified at the honeypot are verified before being distributed to real email systems. This feedback loop with verification reduces false positives while maintaining improved protection capabilities

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis and validation of malware indicators at the honeypot before distributing them to real email systems. This preliminary action filters out false positives early in the process, ensuring that only validated malware indicators are applied to real user systems

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8549642B2Method and system for using spam e-mail honeypots to identify potential malware containing e-mails
Publication Date: 2013.10.01 GEN DIGITAL INC
  • US8549642B2 patent drawing
  • US8549642B2 patent drawing
  • US8549642B2 patent drawing

AI summary

A method and apparatus for employing honeypot systems to identify potential malware containing messages whereby a decoy system to receive illegitimate e-mails is established. E-mails sent to the spam e-mail honeypot decoy are initially scanned/filtered and e-mails that are not considered possible malware containing e-mails are filtered out while the remaining e-mails sent to the spam e-mail honeypot decoy are identified as potential malware containing e-mails. One or more features, and/or feature values, of the identified e-mails are then identified, extracted and ranked. Once a given feature, and/or feature value, occurs more than a burst threshold number of times, the status of the given feature, and/or feature value, is transformed to that of suspicious e-mail parameter.