Causality-based detector for stealthy malware network traffic
This technology watches all network activity on a computer and traces each connection back to its origin — specifically, whether a human user action (like clicking a link or opening a browser) was the root cause. It builds a map of parent-child relationships between network events using signals like timestamps, domain names, process IDs, and HTTP referral fields. If a network event can't be traced back to a legitimate user-initiated trigger, the system flags it as likely malware-generated. This approach catches stealthy malware that tries to blend in with normal traffic rather than triggering traditional signature-based alerts.
What you could build
An endpoint or network security agent that detects command-and-control traffic and data exfiltration from advanced persistent threats (APTs) without relying on known malware signatures; enterprise IT security teams and managed security service providers (MSSPs) would be the primary buyers.
Who in Virginia should care
Northern Virginia's dense concentration of federal contractors, MSSPs, and defense primes (e.g., MITRE, Leidos, Booz Allen) makes this directly relevant to cyber programs serving DoD and Intelligence Community customers.
Readiness: Prototype likely
Concept — described but not yet demonstrated. Lab validated — supported by experimental results in the patent. Prototype likely — the text describes a built, working embodiment.
Readiness is inferred from the patent text, not from a lab visit.
The record
- Inventors
- Danfeng Yao, Hao Zhang
- Granted
- February 6, 2018
- Status
- Granted patent
- Patent number
- 9888030
Ready to talk?
Virginia Tech Intellectual Properties handles licensing for this technology.
Prosim summaries are generated from public patent text and are not legal advice.