Anomaly-Based Malware Detection via Event Pattern Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection methods are inefficient in identifying malicious behavior due to the increasing obfuscation of malware, requiring resource-intensive disassembly or inspection of code, and struggle to detect patterns indicative of attacks without causing false positives or negatives.
Innovation Solution
A system that monitors events on computing devices, analyzes patterns in event data, and scores them based on frequency and similarity across multiple devices to detect and classify malicious activity, using a security agent to interact with a cloud-based security system to identify and mitigate malware without requiring code inspection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional malware detection methods are used, then code inspection and disassembly can be performed, but the process becomes resource-intensive and time-consuming
Solution Approach 1:
The patent replaces traditional mechanical code inspection and disassembly methods with an anomaly-based detection system that monitors behavioral patterns and event sequences. Instead of manually analyzing code structure, the system automatically detects malicious behavior by comparing observed events against established patterns, significantly reducing detection time while maintaining accuracy.
Solution Approach 2:
The system changes the detection parameters from static code analysis to dynamic behavioral pattern monitoring. By tracking changes in event sequences, system calls, and operational patterns over time, the system can identify malware based on anomalous behavior rather than requiring resource-intensive code disassembly.
2Object-affected harmful factors
If malware is increasingly obfuscated to avoid detection, then evasion capability improves, but detection difficulty increases
Solution Approach 1:
Instead of trying to analyze and deobfuscate malware code directly, the system inverts the approach by monitoring the behavioral effects and event patterns produced by the malware. This inversion allows detection without confronting the obfuscated code directly, making the detection process independent of malware obfuscation techniques.
Solution Approach 2:
The system introduces an intermediary layer of behavioral pattern analysis between the malware and the detection system. Rather than directly analyzing malicious code, the intermediary monitors system events, calls, and operational patterns, translating complex obfuscated behavior into detectable anomaly patterns.
3Productivity
If pattern analysis is performed to detect malicious behavior, then detection efficiency improves, but false positives and negatives may occur
Solution Approach 1:
The system implements feedback mechanisms that continuously refine detection patterns based on observed behavior and outcomes. By monitoring the results of detected patterns and adjusting the anomaly detection algorithms accordingly, the system reduces false positives and negatives over time while maintaining high detection efficiency.
Solution Approach 2:
The system employs partial pattern matching and selective monitoring of critical event sequences rather than requiring complete pattern matches. This partial action approach allows the system to detect malicious behavior even when patterns are partially obscured or modified, reducing false negatives while maintaining efficiency.
Data Source
AI summary
Example techniques detect incidents based on events from or at monitored computing devices. A control unit can detect events of various types within a time interval and aggregate the detected events into an incident. The control unit can detect patterns within the events based at least in part on predetermined criterion. In examples, the control unit can determine pattern scores for the patterns based on the probability of occurrence for the patterns and determine a composite score based on the pattern scores. The control unit can determine that an incident indicating malicious activity has been detected based in part determining that the composite score is above a predetermined threshold score. In some examples, the control unit can classify and rank the incidents. The control unit can determine if an incident indicates malicious activity including malware or targeted attack.


