IP Library Granted Patent US 12,450,346
Granted Patent B2
US 12,450,346 · App. 18/344,803 · Granted Oct 21, 2025

Malware beacon detection system

Inventors: Harshvardhan Parmar (Herndon, VA); Vinod Vasudevan (Fairfax, VA)
Assignee: BULL SAS
G06F21/561H04L63/1416H04L63/1425H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,450,346
App. No.
18/344,803
Granted
Oct 21, 2025
Kind
B2
Abstract

A system that detects malware by analyzing message logs to identify message patterns that are periodic with similar-sized messages. These patterns may indicate malware since malware often sends beacon messages to a command-and-control system that are often periodic and of relatively similar length. The system may group message logs by the combination of source and destination and analyze each group for patterns of periodicity and message length uniformity. Entropy may be used to measure the uniformity of message lengths and message intervals, with low (or zero) entropy suggesting malware. Message intervals that repeat after several messages may be detected by testing subsequence sums for uniformity at different possible periods. Additional factors may be used to assess the risk, such as the duration of communication, and threat intelligence on the source or destination. The system may perform automated actions to eliminate or mitigate detected risks, such as blocking further communication.

Claims (64)

1. A malware beacon detection system comprising:

a memory comprising software instructions; and,

a computer or a server comprising a processor that executes said software instructions configured to

receive a multiplicity of message logs, each message log of said multiplicity of message logs comprising

a source;

a destination;

a timestamp; and

a message length;

group said multiplicity of message logs into at least one communication pair group, wherein each communication pair group of said at least one communication pair group comprises message logs of said multiplicity of message logs having a same source and a same destination;

for each of said at least one communication pair group

calculate a message interval series comprising differences between said timestamp associated with successive message logs in each of said at least one communication pair group;

calculate a message length series comprising said message length for each message log in each of said at least one communication pair group;

calculate a length uniformity score that measures how closely said message length series conforms to a constant sequence;

for each period greater than or equal to one message interval and less than or equal to half of a length of said message interval series,

partition said message interval series into subsequences of length equal to said each period;

calculate a subsequence sum series comprising a sum of each subsequence of said subsequences;

calculate an entropy of said subsequence sum series;

calculate a periodicity score as a minimum entropy of said subsequence sum series across said each period greater than or equal to one message interval and less than or equal to said half of the length of said message interval series; and

calculate a malware beacon risk score as a function of said periodicity score and on said length uniformity score,

wherein said malware beacon risk score is a quantitative or qualitative ranking comprising a range of low threat, medium threat and high threat; and,

perform one or more automated response actions that is triggered based on said malware beacon risk score to eliminate or mitigate a malware threat,

wherein said one or more automated response actions are performed dependent on whether said malware beacon risk score is ranked as said low threat, said medium threat or said high threat, such that each automated response action of said one or more automated response actions is different and configured for each of said low threat, said medium threat and said high threat.

2. The malware beacon detection system of claim 1 , wherein said processor is further configured to remove outliers from said message interval series and from said message length series before calculating said periodicity score and said length uniformity score.

3. The malware beacon detection system of claim 1 , wherein said periodicity score comprises an entropy of said message interval series.

4. The malware beacon detection system of claim 1 , wherein said length uniformity score comprises an entropy of said message length series.

5. The malware beacon detection system of claim 1 , wherein said periodicity score comprises a degree to which said message interval series repeats.

6. The malware beacon detection system of claim 5 , wherein said degree to which said message interval series repeats according to said period is calculated by

calculating said degree to which said message interval series repeats according to said period as a measure of how closely said subsequence sum series conforms to said constant sequence.

7. The malware beacon detection system of claim 6 , wherein said measure of how closely said subsequence sum series conforms to said constant sequence comprises an entropy of said subsequence sum series.

8. The malware beacon detection system of claim 1 , wherein said malware beacon risk score is further based on a duration of communications between said source and said destination.

9. The malware beacon detection system of claim 1 , wherein said malware beacon risk score is further based on a threat assessment score assigned to one or both of said source and said destination.

10. The malware beacon detection system of claim 1 , wherein said malware beacon risk score is further based on a size of one or more messages between said source and said destination.

11. The malware beacon detection system of claim 1 , wherein said malware beacon risk score is further based on whether communication between said source and said destination is detected on multiple systems.

12. The malware beacon detection system of claim 1 , wherein said malware beacon risk score is further based on a request method utilized in communication between said source and said destination.

13. The malware beacon detection system of claim 1 , wherein said malware beacon risk score is further based on a resource type accessed in communication between said source and said destination.

14. The malware beacon detection system of claim 1 , wherein said one or more automated response actions comprise one or more of blocking outbound traffic on network devices, isolating an endpoint on a network, launching a system scan, and adding assets to a watchlist.

15. A malware beacon detection system comprising:

a memory comprising software instructions; and,

a computer or a server comprising a processor that executes said software instructions configured to

receive a multiplicity of message logs, each message log of said multiplicity of message logs comprising

a source;

a destination;

a timestamp; and

a message length;

group said multiplicity of message logs into at least one communication pair group, wherein each communication pair group of said at least one communication pair group comprises message logs of said multiplicity of message logs having a same source and a same destination;

for each communication pair group,

calculate

a message interval series comprising differences between said timestamp associated with successive message logs in each of said at least one communication pair group;

a message length series comprising said message length for each message log in each of said at least one communication pair group;

remove outliers from said message interval series and from said message length series;

for each period greater than or equal to one message interval and less than or equal to half of a length of said message interval series,

partition said message interval series into subsequences of length equal to said each period;

calculate a subsequence sum series comprising a sum of each subsequence of said subsequences;

calculate an entropy of said subsequence sum series;

calculate a periodicity score as a minimum entropy of said subsequence sum series across said each period greater than or equal to one message interval and less than or equal to said half of the length of said message interval series;

calculate a length uniformity score based on an entropy of said message length series;

calculate a malware beacon risk score as a function of

said periodicity score;

said length uniformity score;

a duration of communications between said source and said destination; and

a threat assessment score assigned to one or both of said source and said destination,

 wherein said malware beacon risk score is a quantitative or qualitative ranking comprising a range of low threat, medium threat and high threat; and,

perform one or more automated response actions that is triggered based on said malware beacon risk score to eliminate or mitigate a malware threat,

wherein said one or more automated response actions are performed dependent on whether said malware beacon risk score is ranked as said low threat, said medium threat or said high threat, such that each automated response action of said one or more automated response actions is different and configured for each of said low threat, said medium threat and said high threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: PARMAR, HARSHVARDHAN; VASUDEVAN, VINOD
To: BULL SAS
Reel/Frame 064120/0419 →
Continuity (1)
Related Publication 20250005151A1 · Jan 2, 2025
References Cited (23)
US 8578493B1 · Cowan · 2013 [cited by examiner]
US 9038178B1 · Lin · 2015 [cited by examiner]
US 9380066B2 · Hohndel · 2016 [cited by examiner]
US 10284584B2 · Hu · 2019 [cited by examiner]
US 10757136B2 · Fridman · 2020 [cited by examiner]
US 12088611B1 · Lin · 2024 [cited by examiner]
US 12199997B1 · Lin · 2025 [cited by examiner]
US 12323389B2 · Jia · 2025 [cited by examiner]
US 20140344935A1 · Duan · 2014 [cited by examiner]
US 20160014147A1 · Zoldi · 2016 [cited by examiner]
US 20170063921A1 · Fridman · 2017 [cited by examiner]
US 20170244731A1 · Hu · 2017 [cited by examiner]
US 20190020663A1 · Bartos · 2019 [cited by examiner]
US 20200014707A1 · Xie · 2020 [cited by examiner]
US 20200304522A1 · Singh · 2020 [cited by examiner]
US 20210360015A1 · Mammadli · 2021 [cited by examiner]
US 20240039893A1 · Jia · 2024 [cited by examiner]
US 20240039952A1 · Jia · 2024 [cited by examiner]
CN 113114671A · 2021 [cited by examiner]
CN 114422207A · 2022 [cited by examiner]
Y.-R. Yeh, T. C. Tu, M.-K. Sun, S. M. Pi and C . . . -Y. Huang, “A Malware Beacon of Botnet by Local Periodic Communication Behavior,” 2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC), Tokyo… [cited by examiner]
X. Hu et al., “BAYWATCH: Robust Beaconing Detection to Identify Infected Hosts in Large-Scale Enterprise Networks,” 2016 46th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), Toulouse,… [cited by examiner]
European Search Report and Written Opinion issued in EP24181430.0, dated Nov. 20, 2024, and English translations thereof. [cited by applicant]