Bare Metal Sandboxed System for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems are inadequate in effectively addressing advanced persistent threats (APT) and targeted malware, as they often fail to detect and neutralize malware without causing harm to the system and can be evaded by malicious software designed to detect virtual or emulated environments.

Innovation Solution

The implementation of sandboxed systems that run on 'bare metal' without emulation, combined with hardware and software analysis tools, to execute and analyze binary objects in a controlled environment, allowing for the detection of malware without permanent harm and deception of the malware into thinking it's executing on a normal computer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sandboxed systems use emulation to run malware, then malware can be executed in a controlled environment, but malware can detect the virtual environment and evade analysis

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the virtualization/emulation layer from the sandboxed system, transitioning to 'bare metal' execution. This removes the detection target that malware uses to identify virtual environments, thereby improving detection reliability while reducing system complexity by eliminating the emulation infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a specialized hardware platform that acts as an intermediary between the malware and the analysis system. This hardware provides physical I/O capabilities and a controlled execution environment without requiring software emulation, allowing malware to execute authentically while remaining isolated and monitorable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If traditional security systems analyze malware, then malware detection is attempted, but the malware can cause harm to the system before detection

Engineering Contradiction:
Improvemalware analysis efficiencyVSAvoidsystem harm
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements protective measures beforehand by isolating the malware execution in a sandboxed hardware environment with controlled I/O capabilities. This cushioning approach allows malware to execute and exhibit harmful behavior without the ability to actually harm the host system, as all outputs are monitored and contained within the sandboxed platform.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The system segments the analysis environment into isolated sandboxed instances, each capable of running malware independently. This segmentation allows multiple malware samples to be analyzed simultaneously in separate controlled environments, improving productivity while containing harmful effects within individual segments that cannot affect the main system.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security systems use virtualized environments for malware analysis, then malware can be contained, but the virtualization overhead reduces analysis speed

Engineering Contradiction:
Improvemalware containmentVSAvoidanalysis speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent replaces the software-based virtualization mechanism with a hardware-based sandboxed platform. This substitution eliminates the overhead of software emulation and virtualization layers, allowing malware to execute natively at full speed while still maintaining containment through hardware-enforced isolation and controlled I/O interfaces.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10339300B2Advanced persistent threat and targeted malware defense
Publication Date: 2019.07.02 BINARY GUARD CORP
  • US10339300B2 patent drawing
  • US10339300B2 patent drawing
  • US10339300B2 patent drawing

AI summary

Novel tools and techniques are implemented for providing computer security. In various embodiments, a computer system might receive data from one or more data feeds, might obtain a binary object based on the data, might load the binary object onto a sandboxed system, and might execute the binary object with the sandbox system. The computer system might analyze operation of the sandboxed system to determine whether the binary object includes a malware payload, and might, based on a determination that the binary object includes a malware payload, generate a report indicating that the binary object includes a malware payload.