Anomaly Detection for Polymorphic Malware via Metadata Outliers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection methods struggle to identify polymorphic threats that mimic legitimate objects, making it difficult to detect and prevent malicious activity effectively.
Innovation Solution
A communication system utilizing a centralized metadata database to identify highly prevalent uniform objects and detect low prevalence outliers, which can indicate potentially malicious activity by analyzing network traffic and device behavior, including polymorphic threats that mimic legitimate objects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional malware detection methods are used, then detection of known malware is effective, but detection of polymorphic threats that mimic legitimate objects is difficult
Solution Approach 1:
Instead of trying to detect malware by its malicious characteristics, the patent inverts the approach by detecting legitimate objects through their uniformity and prevalence patterns. By establishing what normal objects should look like across the network and identifying deviations from these patterns, the system can detect polymorphic threats that mimic legitimate objects without requiring direct knowledge of malware signatures.
Solution Approach 2:
The patent introduces metadata as an intermediary layer between the actual objects and the detection process. By analyzing metadata characteristics (such as prevalence, uniformity, and distribution patterns) rather than directly examining the objects themselves, the system can identify anomalies that indicate polymorphic threats while maintaining adaptability to new threat types.
2Extent of automation
If automated anomaly detection is implemented, then detection of malicious activity is enhanced, but system complexity increases
Solution Approach 1:
The system implements self-service by automatically establishing baselines for legitimate object behavior and autonomously detecting deviations without requiring manual configuration or intervention. The automated anomaly detection mechanism continuously monitors metadata patterns, learns normal behavior automatically, and identifies threats independently, reducing the need for complex manual management despite the enhanced automation capability.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
Particular embodiments described herein provide for an electronic device that can be configured to monitor activities of objects in a system, compare the monitored activities to metadata for the system, and identify low prevalence outliers to detect potentially malicious activity. The monitored activities can include an analysis of metadata of the objects in the system to identify polymorphic threats, an object reuse analysis of the system to detect an object reusing metadata from another object, and a filename analysis of the system.