Back to the portfolio

Causality-based detector for stealthy malware network traffic

CybersecurityComputing, Software & AICommunications & RFPrototype likely

This technology watches all network activity on a computer and traces each connection back to its origin — specifically, whether a human user action (like clicking a link or opening a browser) was the root cause. It builds a map of parent-child relationships between network events using signals like timestamps, domain names, process IDs, and HTTP referral fields. If a network event can't be traced back to a legitimate user-initiated trigger, the system flags it as likely malware-generated. This approach catches stealthy malware that tries to blend in with normal traffic rather than triggering traditional signature-based alerts.

What you could build

An endpoint or network security agent that detects command-and-control traffic and data exfiltration from advanced persistent threats (APTs) without relying on known malware signatures; enterprise IT security teams and managed security service providers (MSSPs) would be the primary buyers.

Who in Virginia should care

Northern Virginia's dense concentration of federal contractors, MSSPs, and defense primes (e.g., MITRE, Leidos, Booz Allen) makes this directly relevant to cyber programs serving DoD and Intelligence Community customers.

Readiness: Prototype likely

Concept — described but not yet demonstrated. Lab validated — supported by experimental results in the patent. Prototype likely — the text describes a built, working embodiment.

Readiness is inferred from the patent text, not from a lab visit.

The record

Inventors
Danfeng Yao, Hao Zhang
Granted
February 6, 2018
Status
Granted patent
Patent number
9888030

Ready to talk?

Virginia Tech Intellectual Properties handles licensing for this technology.

VTIP contact coming shortly

Prosim summaries are generated from public patent text and are not legal advice.