Network Worm Detection via Transitive Propagation Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current worm detection technologies face challenges in detecting previously undiscovered worms and keeping pace with increasing network bandwidth and traffic loads, often requiring significant computational resources and lacking timely, actionable information for quick response to potential infections.
Innovation Solution
Monitoring network traffic for transitive propagation patterns, where data communication arrives at a node and propagates to another within a prescribed interval, allowing for real-time detection and responsive action, such as alerting or isolating infected systems, using a modified network device like a switch or router equipped with a transitive propagation analysis engine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If exploit and vulnerability signature approach is used, then detection accuracy for known worms is improved, but ability to detect previously undiscovered worms deteriorates
Solution Approach 1:
The system performs preliminary actions by monitoring network traffic for transitive propagation patterns before full worm infection occurs. By detecting the propagation behavior itself rather than relying on pre-compiled signatures, the system can identify new worms as they propagate through the network, enabling early detection without requiring prior knowledge of specific worm signatures.
2Reliability
If anti-virus and IPS systems process network traffic, then worm detection capability is improved, but processing capacity relative to network bandwidth deteriorates
Solution Approach 1:
The invention extracts only the critical transitive propagation behavior patterns from the vast amount of network traffic for analysis. Instead of processing every packet in detail, the system identifies and focuses on traffic that exhibits the specific pattern of arriving at a node and propagating to another within a prescribed interval, thereby reducing processing requirements while maintaining detection effectiveness.
Solution Approach 2:
The system applies partial action by monitoring only the propagation behavior aspect of network traffic rather than performing complete packet inspection. This selective monitoring approach allows the system to maintain reliable worm detection while operating within acceptable processing capacity constraints relative to network bandwidth.
3Adaptability or versatility
If macro behavior observations are used, then independence from worm signatures is improved, but timeliness of actionable information deteriorates
Solution Approach 1:
The system performs preliminary detection of transitive propagation patterns as they occur in real-time network traffic. By monitoring for the specific behavior pattern of data arriving at a node and propagating to another within a prescribed interval, the system can trigger alerts immediately when worm propagation is detected, providing timely actionable information before the macro behavior anomalies become significant enough to trigger traditional anomaly-based alerts.
Data Source
AI summary
Detecting a network worm is disclosed. Network traffic between a plurality of network nodes is monitored to determine if the traffic exhibits a characteristic associated with worm propagation. Responsive action is taken if it is determined that a portion of the network traffic does exhibit the characteristic associated with worm propagation. The characteristic associated with worm propagation comprises a data communication or a variant thereof arriving at a first node and propagating from the first node to a second node within a prescribed interval after arriving at the first node.


