Anomaly-Based Malware Detection via Event Pattern Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection methods are inefficient in identifying malicious behavior due to the increasing obfuscation of malware, requiring resource-intensive disassembly or inspection of code, and struggle to detect patterns indicative of attacks without causing false positives or negatives.

Innovation Solution

A system that monitors events on computing devices, analyzes patterns in event data, and scores them based on frequency and similarity across multiple devices to detect and classify malicious activity, using a security agent to interact with a cloud-based security system to identify and mitigate malware without requiring code inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional malware detection methods are used, then code inspection and disassembly can be performed, but the process becomes resource-intensive and time-consuming

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces traditional mechanical code inspection and disassembly methods with an anomaly-based detection system that monitors behavioral patterns and event sequences. Instead of manually analyzing code structure, the system automatically detects malicious behavior by comparing observed events against established patterns, significantly reducing detection time while maintaining accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the detection parameters from static code analysis to dynamic behavioral pattern monitoring. By tracking changes in event sequences, system calls, and operational patterns over time, the system can identify malware based on anomalous behavior rather than requiring resource-intensive code disassembly.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If malware is increasingly obfuscated to avoid detection, then evasion capability improves, but detection difficulty increases

Engineering Contradiction:
Improvemalware evasion capabilityVSAvoiddetection difficulty
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

Instead of trying to analyze and deobfuscate malware code directly, the system inverts the approach by monitoring the behavioral effects and event patterns produced by the malware. This inversion allows detection without confronting the obfuscated code directly, making the detection process independent of malware obfuscation techniques.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system introduces an intermediary layer of behavioral pattern analysis between the malware and the detection system. Rather than directly analyzing malicious code, the intermediary monitors system events, calls, and operational patterns, translating complex obfuscated behavior into detectable anomaly patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If pattern analysis is performed to detect malicious behavior, then detection efficiency improves, but false positives and negatives may occur

Engineering Contradiction:
Improvedetection efficiencyVSAvoiddetection reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanisms that continuously refine detection patterns based on observed behavior and outcomes. By monitoring the results of detected patterns and adjusting the anomaly detection algorithms accordingly, the system reduces false positives and negatives over time while maintaining high detection efficiency.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system employs partial pattern matching and selective monitoring of critical event sequences rather than requiring complete pattern matches. This partial action approach allows the system to detect malicious behavior even when patterns are partially obscured or modified, reducing false negatives while maintaining efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11277423B2Anomaly-based malicious-behavior detection
Publication Date: 2022.03.15 CROWDSTRIKE
  • US11277423B2 patent drawing
  • US11277423B2 patent drawing
  • US11277423B2 patent drawing

AI summary

Example techniques detect incidents based on events from or at monitored computing devices. A control unit can detect events of various types within a time interval and aggregate the detected events into an incident. The control unit can detect patterns within the events based at least in part on predetermined criterion. In examples, the control unit can determine pattern scores for the patterns based on the probability of occurrence for the patterns and determine a composite score based on the pattern scores. The control unit can determine that an incident indicating malicious activity has been detected based in part determining that the composite score is above a predetermined threshold score. In some examples, the control unit can classify and rank the incidents. The control unit can determine if an incident indicates malicious activity including malware or targeted attack.