Threat Information Extraction Using Packet Header Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques face difficulties in extracting threat information unrelated to malware, particularly in identifying infected hosts and scaling for networks with encrypted communications, such as carrier networks.
Innovation Solution
A threat information extraction device that analyzes packet headers using a network information DB and threat information extraction unit to generate new threat information by estimating feature values from IP addresses and identifying similar communication patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If malware behavior analysis is used to extract threat information, then threat information related to malware can be extracted, but threat information unrelated to malware or concerning macro malware behavior across the network cannot be extracted
Solution Approach 1:
The patent segments the threat information extraction process into two distinct modules: (1) malware behavior analysis for extracting malware-related threat information, and (2) packet header analysis for extracting general network threat information. This segmentation allows each module to specialize in different types of threats, thereby improving overall extraction completeness while maintaining adaptability to various threat types.
Solution Approach 2:
The patent creates a universal threat information extraction system that handles both malware-specific threats and general network threats through a multi-functional architecture. The packet header analysis component serves as a universal mechanism that can detect various types of network threats (DDoS, port scanning, suspicious communications) regardless of whether they involve malware, thus improving versatility across different threat types.
2Measurement precision
If payload analysis is used to extract attack communication, then attack communication can be extracted, but the technique cannot be applied to networks with encrypted communications
Solution Approach 1:
The patent extracts and analyzes only the packet header information (source IP, destination IP, port numbers, protocol types) while deliberately excluding the need to decrypt or analyze the encrypted payload. This extraction approach maintains high detection accuracy for communication patterns while being fully compatible with encrypted networks, as headers remain visible even when payload content is encrypted.
Solution Approach 2:
The patent uses packet header information as an intermediary that bridges the gap between needing to detect attack communication and the inability to access encrypted payload content. By analyzing headers as a mediator layer, the system can identify suspicious communication patterns (such as C2 server communications or DDoS traffic) without requiring decryption, thus maintaining both accuracy and versatility.
3Loss of information
If malware observation is used to extract threat information, then malware-related communication destinations can be extracted, but it is extremely difficult to exhaustively observe related behavior about all malware codes
Solution Approach 1:
The patent implements a dynamic threat information extraction approach where the system continuously adapts to new malware variants by analyzing packet headers in real-time. Instead of attempting static exhaustive observation of all malware codes, the system dynamically adjusts its detection patterns based on observed communication behaviors, making the extraction process adaptable and scalable without requiring complex pre-programming for every possible malware type.
Solution Approach 2:
The packet header analysis component serves itself by automatically identifying suspicious communication patterns without requiring manual malware signature updates or complex analysis rules. The system self-adapts to new threats by learning from observed network traffic patterns, thereby achieving exhaustive threat information extraction without proportionally increasing system complexity.
4Productivity
If flow information analysis is performed to estimate communication features, then new threat information can be generated, but the system must process and analyze large volumes of network data
Solution Approach 1:
The patent extracts only the essential and most informative features from flow information (source IP, destination IP, port numbers, protocol types, packet counts) while discarding redundant or less useful data. This selective extraction approach enables efficient threat information generation by focusing computational resources on the most relevant data elements, thereby improving productivity without requiring processing of the entire raw data volume.
Solution Approach 2:
The patent applies different analysis depths and processing intensities to different types of flow information based on their local quality and importance. For example, IP address pairs showing suspicious communication patterns receive more intensive analysis, while normal traffic flows receive lighter processing. This localized quality approach optimizes the balance between threat information generation efficiency and data processing volume.
Data Source
AI summary
The present invention discloses a technique for extending threat information and/or generating new threat information by analyzing packet headers flowing through a network using threat information obtained by analyzing malware behavior or the like. An aspect of the present invention relates to a threat information extraction device provided with a network information DB that stores flow information and a threat information extraction unit that extracts new threat information from acquired threat information using the flow information, in which the threat information extraction unit extracts a first IP address from the acquired threat information, creates totalization information on the first IP address from the flow information, estimates a feature value of communication associated with the first IP address from the totalization information, extracts zero or one or more other IP addresses similar to the first IP address at which communication is in progress based on the estimated feature value and generates threat information.


