Trained Classifier Detects Malicious C2 Cloud Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Detecting and blocking malicious command and control (C2) traffic between cloud resources and malware on an infected host is challenging due to the difficulty in distinguishing benign from malicious traffic without causing excessive false-positives or false-negatives, especially when using cloud services that are sanctioned for legitimate purposes.
Innovation Solution
A network security system (NSS) intercepts and analyzes cloud traffic, extracts features to identify beaconing behavior, anomalous entities, and other suspicious signals, and uses a trained classifier to classify traffic as malicious or benign, blocking further communication with malicious resources while allowing benign traffic to pass through.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security methods are used to detect malicious C2 traffic, then detection capability is improved, but false-positives increase and legitimate cloud services are disrupted
Solution Approach 1:
The patent changes the detection parameters from traditional signature-based methods to machine learning-based behavioral analysis. The system extracts multiple features (beaconing behavior, anomalous entities, suspicious signals) and uses a trained classifier to detect malicious traffic, allowing for more nuanced detection that reduces false-positives while maintaining detection capability.
Solution Approach 2:
The patent replaces traditional mechanical security detection methods with a machine learning-based classification system. The trained classifier automatically analyzes traffic patterns and makes detection decisions, substituting manual rule-based security mechanisms with an adaptive intelligent system that better distinguishes malicious from legitimate traffic.
2Reliability
If cloud services are blocked to prevent malicious C2 traffic, then network security is improved, but user experience degrades due to disruption of legitimate services
Solution Approach 1:
The patent applies local quality by treating different cloud traffic differently based on its characteristics. Instead of blanket blocking all cloud traffic, the system analyzes individual traffic flows using extracted features and applies selective blocking only to malicious traffic identified by the classifier, allowing legitimate services to continue uninterrupted.
Solution Approach 2:
The patent introduces a trained classifier as an intermediary between cloud traffic and the blocking mechanism. This intermediary intelligently evaluates traffic and makes decisions about which flows to block, serving as a mediator that protects security while preserving legitimate user access to cloud services.
3Measurement precision
If machine learning classifier is used to detect malicious traffic, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent segments the detection system into distinct functional modules: feature extraction module that identifies specific traffic characteristics, training module that develops the classifier model, and classification module that applies the trained model to detect malicious traffic. This segmentation manages complexity by organizing the machine learning system into manageable, specialized components.
Solution Approach 2:
The patent performs preliminary action by training the classifier model in advance using labeled training data before deployment. The training phase prepares the detection system with pre-learned patterns of malicious and legitimate traffic, so that during operation, the system can quickly and accurately classify new traffic without requiring complex real-time analysis.
Data Source
AI summary
The technology disclosed relates to a method, system, and non-transitory computer-readable media that classifies cloud traffic between a client and cloud application as malicious command and control (C2) cloud traffic or benign cloud traffic. A cloud traffic classifier, in communication with a network security system, is provided intercepted cloud traffic as an input, and generate an output that classifies the cloud traffic as malicious command and control (C2) cloud traffic or benign cloud traffic. The classifier may use signals such as beaconing behavior, anomalous entity, anomalous agent, anomalous username, anomalous username, anomalous agent, cat's paw behavior of the client, anomalous hostname access patterns, and/or malicious task sequence execution.


