Malware-Usable Clean File Detection via Segmented Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware scanning software and hardware are unable to detect malware that uses clean files as a launch mechanism or for sandbox escape, as these files are not identified as malware despite being vulnerable to malicious usage.

Innovation Solution

A method and apparatus for identifying vulnerable clean files in a computer system, checking their threat potential, and detecting them as malware-usable by verifying reputation, registration, launchpoint, installation, and presence information, allowing for the detection of malware using clean files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional malware scanning software is used, then malware files can be identified, but malware using clean files cannot be detected

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidability to detect malware using clean files
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The detection process is segmented into multiple independent verification steps: reputation information verification, device presence verification, launchpoint verification, installation information verification, and expected state verification. Each segment checks a specific aspect of the clean file's legitimacy, allowing comprehensive detection without treating the entire file as malware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary verification of clean files before they are executed or used by malware. By checking reputation information, device presence, launchpoint, installation information, and expected state in advance, the system prevents malware from successfully utilizing clean files for malicious purposes.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If clean files are monitored for malware usage, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvedetection accuracy of malware-usable clean filesVSAvoidcomplexity of verification process
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The complex verification process is divided into five manageable verification modules, each handling a specific type of information (reputation, device presence, launchpoint, installation, expected state). This segmentation reduces the perceived complexity by organizing the verification process into discrete, independent tasks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary verification mechanism that acts as a mediator between the clean file and the execution environment. This intermediary layer performs multiple checks without requiring the clean file itself to be modified, simplifying the overall system architecture while maintaining high detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple verification checks are performed on clean files, then false positives decrease, but processing time increases

Engineering Contradiction:
Improvereduction of false positivesVSAvoidtime for verification process
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Verification checks are performed preliminarily, before the clean file is executed or utilized by malware. This preliminary action allows the system to identify and block malicious usage before it occurs, reducing false positives during actual operations while maintaining efficient processing through advance validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification system uses self-service mechanisms by checking multiple attributes of the clean file (reputation, device presence, launchpoint, installation information, expected state) that are inherently available in the system. This approach reduces processing time by leveraging existing system information rather than requiring extensive external validation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10282545B2Detection of malware-usable clean file
Publication Date: 2019.05.07 F SECURE CORP
  • US10282545B2 patent drawing
  • US10282545B2 patent drawing
  • US10282545B2 patent drawing

AI summary

There are provided measures for enabling the detection of a malware-usable clean file or, stated differently, the detection of malware using a clean file. Such measures could exemplarily include identifying a vulnerable clean file in a computer system, which does not constitute malware but is vulnerable for usage by malware, checking the vulnerable clean file for its threat of usage by malware, and detecting the vulnerable clean file as malware-usable clean file on the basis of a result of said checking of its threat of usage by malware.