Network Worm Detection via Transitive Propagation Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current worm detection technologies face challenges in detecting previously undiscovered worms and keeping pace with increasing network bandwidth and traffic loads, often requiring significant computational resources and lacking timely, actionable information for quick response to potential infections.

Innovation Solution

Monitoring network traffic for transitive propagation patterns, where data communication arrives at a node and propagates to another within a prescribed interval, allowing for real-time detection and responsive action, such as alerting or isolating infected systems, using a modified network device like a switch or router equipped with a transitive propagation analysis engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If exploit and vulnerability signature approach is used, then detection accuracy for known worms is improved, but ability to detect previously undiscovered worms deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect new worms
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by monitoring network traffic for transitive propagation patterns before full worm infection occurs. By detecting the propagation behavior itself rather than relying on pre-compiled signatures, the system can identify new worms as they propagate through the network, enabling early detection without requiring prior knowledge of specific worm signatures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If anti-virus and IPS systems process network traffic, then worm detection capability is improved, but processing capacity relative to network bandwidth deteriorates

Engineering Contradiction:
Improveworm detection capabilityVSAvoidprocessing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The invention extracts only the critical transitive propagation behavior patterns from the vast amount of network traffic for analysis. Instead of processing every packet in detail, the system identifies and focuses on traffic that exhibits the specific pattern of arriving at a node and propagating to another within a prescribed interval, thereby reducing processing requirements while maintaining detection effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial action by monitoring only the propagation behavior aspect of network traffic rather than performing complete packet inspection. This selective monitoring approach allows the system to maintain reliable worm detection while operating within acceptable processing capacity constraints relative to network bandwidth.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If macro behavior observations are used, then independence from worm signatures is improved, but timeliness of actionable information deteriorates

Engineering Contradiction:
Improveindependence from signaturesVSAvoidtimeliness of information
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary detection of transitive propagation patterns as they occur in real-time network traffic. By monitoring for the specific behavior pattern of data arriving at a node and propagating to another within a prescribed interval, the system can trigger alerts immediately when worm propagation is detected, providing timely actionable information before the macro behavior anomalies become significant enough to trigger traditional anomaly-based alerts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7725935B1Detecting worms
Publication Date: 2010.05.25 CA TECH INC
  • US7725935B1 patent drawing
  • US7725935B1 patent drawing
  • US7725935B1 patent drawing

AI summary

Detecting a network worm is disclosed. Network traffic between a plurality of network nodes is monitored to determine if the traffic exhibits a characteristic associated with worm propagation. Responsive action is taken if it is determined that a portion of the network traffic does exhibit the characteristic associated with worm propagation. The characteristic associated with worm propagation comprises a data communication or a variant thereof arriving at a first node and propagating from the first node to a second node within a prescribed interval after arriving at the first node.