Anomaly Detection for Polymorphic Malware via Metadata Outliers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection methods struggle to identify polymorphic threats that mimic legitimate objects, making it difficult to detect and prevent malicious activity effectively.

Innovation Solution

A communication system utilizing a centralized metadata database to identify highly prevalent uniform objects and detect low prevalence outliers, which can indicate potentially malicious activity by analyzing network traffic and device behavior, including polymorphic threats that mimic legitimate objects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional malware detection methods are used, then detection of known malware is effective, but detection of polymorphic threats that mimic legitimate objects is difficult

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect polymorphic threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

Instead of trying to detect malware by its malicious characteristics, the patent inverts the approach by detecting legitimate objects through their uniformity and prevalence patterns. By establishing what normal objects should look like across the network and identifying deviations from these patterns, the system can detect polymorphic threats that mimic legitimate objects without requiring direct knowledge of malware signatures.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces metadata as an intermediary layer between the actual objects and the detection process. By analyzing metadata characteristics (such as prevalence, uniformity, and distribution patterns) rather than directly examining the objects themselves, the system can identify anomalies that indicate polymorphic threats while maintaining adaptability to new threat types.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If automated anomaly detection is implemented, then detection of malicious activity is enhanced, but system complexity increases

Engineering Contradiction:
Improveautomated detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically establishing baselines for legitimate object behavior and autonomously detecting deviations without requiring manual configuration or intervention. The automated anomaly detection mechanism continuously monitors metadata patterns, learns normal behavior automatically, and identifies threats independently, reducing the need for complex manual management despite the enhanced automation capability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3314511B1Anomaly detection to identify malware
Publication Date: 2020.05.06 MCAFEE LLC
  • EP3314511B1 patent drawingFigure 1A
  • EP3314511B1 patent drawingFigure 1B
  • EP3314511B1 patent drawingFigure 2

AI summary

Particular embodiments described herein provide for an electronic device that can be configured to monitor activities of objects in a system, compare the monitored activities to metadata for the system, and identify low prevalence outliers to detect potentially malicious activity. The monitored activities can include an analysis of metadata of the objects in the system to identify polymorphic threats, an object reuse analysis of the system to detect an object reusing metadata from another object, and a filename analysis of the system.