Accelerated Virtual Execution for Malware Domain Collection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware authors use algorithmically generated domains (AGDs) to evade detection, making it difficult for security companies to identify and prevent malware communication with command and control servers, as these domains appear random and are obfuscated by sophisticated domain generation algorithms, requiring months to reverse-engineer and analyze.

Innovation Solution

A data appliance system that includes a DNS module and virtual machine servers to collect and analyze algorithmically generated domains by accelerating malware execution in a virtualized environment, allowing for the identification and prevention of AGDs without needing to reverse-engineer the domain generation algorithm, using techniques such as time acceleration and statistical analysis to monitor and block suspicious domain requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malware authors use algorithmically generated domains to evade detection, then malware can communicate with command and control servers without being blocked, but security companies face increased difficulty and time to detect and prevent malware communication

Engineering Contradiction:
Improvemalware communication reliabilityVSAvoiddomain detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary analysis of domain generation algorithms by collecting and analyzing domains generated by malware samples in isolated environments. This advance preparation creates a database of algorithmic patterns and generated domains before they are used in actual attacks, enabling proactive blocking rather than reactive detection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of malware samples in controlled virtual environments to observe and record the domains they generate. By replicating malware behavior in isolation, the system can collect algorithmic patterns without risking actual system compromise, then use these copied behaviors for detection and prevention

Inventive Principle:
Principle #26Copying

2Measurement precision

If security companies reverse-engineer domain generation algorithms to detect AGDs, then detection capability improves, but the process requires months of time and effort

Engineering Contradiction:
Improvedomain detection precisionVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system allows malware to automatically generate and reveal its own domain patterns by executing malware samples in controlled environments. Instead of manually reverse-engineering algorithms, the malware itself produces the data needed for detection through its normal operation, significantly reducing analysis time while maintaining detection precision

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback loops where collected domain data is continuously analyzed to improve detection algorithms. The system learns from each analyzed malware sample, refining its ability to detect algorithmically generated domains and reducing the time required for future detections through accumulated knowledge

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If malware uses sophisticated obfuscation techniques, then malware can evade security detection, but security companies need more advanced and complex analysis methods to detect it

Engineering Contradiction:
Improvemalware evasion capabilityVSAvoiddetection system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary layer of domain collection and analysis that sits between malware execution and detection. This intermediary automatically captures algorithmic patterns and generated domains, translating sophisticated obfuscation into analyzable data without requiring direct complex analysis of the obfuscation techniques themselves

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11036859B2Collecting algorithmically generated domains
Publication Date: 2021.06.15 PALO ALTO NETWORKS INC
  • US11036859B2 patent drawing
  • US11036859B2 patent drawing
  • US11036859B2 patent drawing

AI summary

Generating a set of attempted external contacts associated with a malware sample is disclosed. A malware sample is executed in an accelerated computing environment. In the accelerated computing environment, a guest time is advanced more quickly than a time by which a host time is advanced. A set of one or more attempted external contacts generated by the executing malware sample is recorded. The set of attempted external contacts includes at least one generated domain name. A remedial action is taken with respect to the generated domain name.