Threat Information Extraction Using Packet Header Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques face difficulties in extracting threat information unrelated to malware, particularly in identifying infected hosts and scaling for networks with encrypted communications, such as carrier networks.

Innovation Solution

A threat information extraction device that analyzes packet headers using a network information DB and threat information extraction unit to generate new threat information by estimating feature values from IP addresses and identifying similar communication patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If malware behavior analysis is used to extract threat information, then threat information related to malware can be extracted, but threat information unrelated to malware or concerning macro malware behavior across the network cannot be extracted

Engineering Contradiction:
Improvethreat information extraction completenessVSAvoidapplicability to different threat types
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The patent segments the threat information extraction process into two distinct modules: (1) malware behavior analysis for extracting malware-related threat information, and (2) packet header analysis for extracting general network threat information. This segmentation allows each module to specialize in different types of threats, thereby improving overall extraction completeness while maintaining adaptability to various threat types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal threat information extraction system that handles both malware-specific threats and general network threats through a multi-functional architecture. The packet header analysis component serves as a universal mechanism that can detect various types of network threats (DDoS, port scanning, suspicious communications) regardless of whether they involve malware, thus improving versatility across different threat types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If payload analysis is used to extract attack communication, then attack communication can be extracted, but the technique cannot be applied to networks with encrypted communications

Engineering Contradiction:
Improveattack communication detection accuracyVSAvoidapplicability to encrypted networks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent extracts and analyzes only the packet header information (source IP, destination IP, port numbers, protocol types) while deliberately excluding the need to decrypt or analyze the encrypted payload. This extraction approach maintains high detection accuracy for communication patterns while being fully compatible with encrypted networks, as headers remain visible even when payload content is encrypted.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses packet header information as an intermediary that bridges the gap between needing to detect attack communication and the inability to access encrypted payload content. By analyzing headers as a mediator layer, the system can identify suspicious communication patterns (such as C2 server communications or DDoS traffic) without requiring decryption, thus maintaining both accuracy and versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If malware observation is used to extract threat information, then malware-related communication destinations can be extracted, but it is extremely difficult to exhaustively observe related behavior about all malware codes

Engineering Contradiction:
Improveexhaustiveness of threat informationVSAvoidcomplexity of exhaustive malware observation
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a dynamic threat information extraction approach where the system continuously adapts to new malware variants by analyzing packet headers in real-time. Instead of attempting static exhaustive observation of all malware codes, the system dynamically adjusts its detection patterns based on observed communication behaviors, making the extraction process adaptable and scalable without requiring complex pre-programming for every possible malware type.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The packet header analysis component serves itself by automatically identifying suspicious communication patterns without requiring manual malware signature updates or complex analysis rules. The system self-adapts to new threats by learning from observed network traffic patterns, thereby achieving exhaustive threat information extraction without proportionally increasing system complexity.

Inventive Principle:
Principle #25Self-service

4Productivity

If flow information analysis is performed to estimate communication features, then new threat information can be generated, but the system must process and analyze large volumes of network data

Engineering Contradiction:
Improvethreat information generation efficiencyVSAvoidvolume of data to be processed
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential and most informative features from flow information (source IP, destination IP, port numbers, protocol types, packet counts) while discarding redundant or less useful data. This selective extraction approach enables efficient threat information generation by focusing computational resources on the most relevant data elements, thereby improving productivity without requiring processing of the entire raw data volume.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different analysis depths and processing intensities to different types of flow information based on their local quality and importance. For example, IP address pairs showing suspicious communication patterns receive more intensive analysis, while normal traffic flows receive lighter processing. This localized quality approach optimizes the balance between threat information generation efficiency and data processing volume.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11546356B2Threat information extraction apparatus and threat information extraction system
Publication Date: 2023.01.03 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11546356B2 patent drawing
  • US11546356B2 patent drawing
  • US11546356B2 patent drawing

AI summary

The present invention discloses a technique for extending threat information and/or generating new threat information by analyzing packet headers flowing through a network using threat information obtained by analyzing malware behavior or the like. An aspect of the present invention relates to a threat information extraction device provided with a network information DB that stores flow information and a threat information extraction unit that extracts new threat information from acquired threat information using the flow information, in which the threat information extraction unit extracts a first IP address from the acquired threat information, creates totalization information on the first IP address from the flow information, estimates a feature value of communication associated with the first IP address from the totalization information, extracts zero or one or more other IP addresses similar to the first IP address at which communication is in progress based on the estimated feature value and generates threat information.