Network Worm Detection via Traffic Matrix Rank Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting network worms are inefficient in detecting unknown worms, particularly in large networks, as they require significant computational resources and memory, and often result in false positives or fail to detect unknown patterns.
Innovation Solution
A method and device that collect network traffic, generate traffic matrices to represent traffic characteristics over different time domains, eliminate legitimate traffic, and calculate a rank value to determine the network state, allowing for early detection of unknown network worms with reduced computational quantity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If pattern-matching-based worm detecting method is used, then detection speed is improved, but unknown worms cannot be detected
Solution Approach 1:
The patent transforms the detection approach from pattern-matching (checking against known signatures) to parameter-based analysis (examining traffic flow characteristics such as packet rates, flow durations, and connection patterns). By monitoring statistical parameters of network traffic rather than matching known worm patterns, the system can detect both known and unknown worms based on their behavioral parameters.
2Adaptability or versatility
If worm-behavior-based detecting method is used, then unknown worms can be detected, but false positives increase and computational quantity increases
Solution Approach 1:
The patent applies partial action by focusing on a selective subset of traffic characteristics rather than analyzing all possible worm behaviors. It monitors specific flow parameters (packet rates, inter-arrival times, connection states) that are most indicative of worm activity, rather than attempting to detect all possible behavioral patterns. This reduces false positives while maintaining detection effectiveness.
Solution Approach 2:
The patent replaces complex behavioral analysis mechanisms with a simpler statistical monitoring approach. Instead of using sophisticated machine learning or behavior modeling systems that require extensive computation, it uses straightforward statistical analysis of traffic flow parameters, substituting a computationally intensive mechanical analysis system with a more efficient statistical approach.
3Adaptability or versatility
If network entropy is used for worm detection, then worm detection capability is improved, but computational quantity increases and applicability to large networks decreases
Solution Approach 1:
The patent extracts and monitors only the essential traffic flow parameters that are most relevant to worm detection, rather than calculating comprehensive network entropy which requires analyzing all traffic characteristics. By extracting and focusing on key parameters such as flow rates, connection patterns, and packet inter-arrival times, the system achieves effective worm detection with reduced computational overhead suitable for large-scale networks.
4Measurement precision
If conventional worm detecting schemes are used, then known worms can be detected, but detection of unknown worms from huge networks fails
Solution Approach 1:
The patent creates a universal detection mechanism that functions for both known and unknown worms through statistical parameter analysis. The same monitoring and analysis framework applies regardless of whether the worm is previously known or newly emerging, making the system universally applicable to all worm types in large networks without requiring separate detection mechanisms.
Data Source
AI summary
A method and device for detecting a network worm on the network allows early detection of an unknown network worm with less computational quantity based on a change of randomness occurring to network traffic without using a pattern-matching-based worm detecting method or a behavior-based worm detecting method.


