Network Worm Detection via Traffic Matrix Rank Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting network worms are inefficient in detecting unknown worms, particularly in large networks, as they require significant computational resources and memory, and often result in false positives or fail to detect unknown patterns.

Innovation Solution

A method and device that collect network traffic, generate traffic matrices to represent traffic characteristics over different time domains, eliminate legitimate traffic, and calculate a rank value to determine the network state, allowing for early detection of unknown network worms with reduced computational quantity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If pattern-matching-based worm detecting method is used, then detection speed is improved, but unknown worms cannot be detected

Engineering Contradiction:
Improvedetection speedVSAvoiddetection capability for unknown worms
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent transforms the detection approach from pattern-matching (checking against known signatures) to parameter-based analysis (examining traffic flow characteristics such as packet rates, flow durations, and connection patterns). By monitoring statistical parameters of network traffic rather than matching known worm patterns, the system can detect both known and unknown worms based on their behavioral parameters.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If worm-behavior-based detecting method is used, then unknown worms can be detected, but false positives increase and computational quantity increases

Engineering Contradiction:
Improvedetection capability for unknown wormsVSAvoiddetection accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent applies partial action by focusing on a selective subset of traffic characteristics rather than analyzing all possible worm behaviors. It monitors specific flow parameters (packet rates, inter-arrival times, connection states) that are most indicative of worm activity, rather than attempting to detect all possible behavioral patterns. This reduces false positives while maintaining detection effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent replaces complex behavioral analysis mechanisms with a simpler statistical monitoring approach. Instead of using sophisticated machine learning or behavior modeling systems that require extensive computation, it uses straightforward statistical analysis of traffic flow parameters, substituting a computationally intensive mechanical analysis system with a more efficient statistical approach.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If network entropy is used for worm detection, then worm detection capability is improved, but computational quantity increases and applicability to large networks decreases

Engineering Contradiction:
Improveworm detection capabilityVSAvoidcomputational quantity
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts and monitors only the essential traffic flow parameters that are most relevant to worm detection, rather than calculating comprehensive network entropy which requires analyzing all traffic characteristics. By extracting and focusing on key parameters such as flow rates, connection patterns, and packet inter-arrival times, the system achieves effective worm detection with reduced computational overhead suitable for large-scale networks.

Inventive Principle:
Principle #2Taking out (Extraction)

4Measurement precision

If conventional worm detecting schemes are used, then known worms can be detected, but detection of unknown worms from huge networks fails

Engineering Contradiction:
Improvedetection accuracy for known wormsVSAvoiddetection capability for unknown worms in huge networks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal detection mechanism that functions for both known and unknown worms through statistical parameter analysis. The same monitoring and analysis framework applies regardless of whether the worm is previously known or newly emerging, making the system universally applicable to all worm types in large networks without requiring separate detection mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8151350B2Method and device for detecting unknown network worms
Publication Date: 2012.04.03 KOREA UNIV IND & ACAD COLLABORATION FOUNDATION
  • US8151350B2 patent drawing
  • US8151350B2 patent drawing
  • US8151350B2 patent drawing

AI summary

A method and device for detecting a network worm on the network allows early detection of an unknown network worm with less computational quantity based on a change of randomness occurring to network traffic without using a pattern-matching-based worm detecting method or a behavior-based worm detecting method.