Anti-Malware Obfuscation via File Randomization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-malware protection methods are insufficient in detecting and defending against the growing complexity and number of malware variants, which can evade detection and destroy anti-malware programs before they are recognized.

Innovation Solution

The method involves obfuscating anti-malware files by randomizing file names, altering file sizes and signatures through polymorphism, and relocating files, making it difficult for malware to locate and target them, and utilizing detection engines to identify malware that attempts to overcome these protections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If anti-malware programs use traditional detection methods (scanners and detection engines) to identify malware, then they can detect known malware signatures, but they become vulnerable to new and complex malware variants that evade detection

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidprotection reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

Instead of trying to detect malware by analyzing its characteristics, the patent inverts the approach by obfuscating the anti-malware program's own files and processes. This makes it difficult for malware to identify and target the anti-malware components, effectively protecting them without requiring perfect malware detection capability

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces an intermediary layer of obfuscation between the malware and the anti-malware program. This intermediary obscures the identification information of anti-malware files, preventing malware from directly targeting them while allowing the anti-malware program to function normally

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If anti-malware programs maintain comprehensive malware libraries and use detection engines to identify all malware variants, then detection capability improves, but the complexity and resource requirements increase significantly

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the identification information from malware and applies it to the anti-malware program itself. Instead of maintaining complex malware libraries, the system uses obfuscation techniques on its own files, simplifying the architecture while maintaining protection effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies detection engine capabilities to the anti-malware program's own files through obfuscation. The same detection principles used for malware are inverted and applied to protect the anti-malware program, eliminating the need for separate complex protection systems

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If malware programs include detection engines to locate and destroy anti-malware files, then their ability to overcome protection increases, but they become larger and produce identifiable signatures that make them easier to detect

Engineering Contradiction:
Improvemalware attack capabilityVSAvoidmalware detectability
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent changes the 'color' or identification characteristics of anti-malware files through obfuscation techniques. By altering file names, paths, and other identifying information, the anti-malware program becomes invisible to malware detection engines, while any malware that attempts to use similar detection methods becomes identifiable through its own signatures

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS7640583B1Method and system for protecting anti-malware programs
Publication Date: 2009.12.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7640583B1 patent drawing
  • US7640583B1 patent drawing
  • US7640583B1 patent drawing

AI summary

In general, embodiments of the present invention provide protection for anti-malware software programs (also referred to herein as anti-malware) that is in addition to the protection that currently exists. In particular, instead of only protecting anti-malware programs from malware attacks by attempting to detect the malware software programs (also referred to herein as malware) before they can accomplish their malicious task, embodiments of the present invention obfuscate, or hide, the anti-malware and/or files associated with the anti-malware. Obfuscating files makes it difficult for malware to locate the information needed to accomplish its malware tasks. Additionally, because obfuscation makes file location difficult, malware that attempts to overcome this protection technique will likely include or use a detection engine.