Malware-Usable Clean File Detection via Segmented Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional malware scanning software and hardware are unable to detect malware that uses clean files as a launch mechanism or for sandbox escape, as these files are not identified as malware despite being vulnerable to malicious usage.
Innovation Solution
A method and apparatus for identifying vulnerable clean files in a computer system, checking their threat potential, and detecting them as malware-usable by verifying reputation, registration, launchpoint, installation, and presence information, allowing for the detection of malware using clean files.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional malware scanning software is used, then malware files can be identified, but malware using clean files cannot be detected
Solution Approach 1:
The detection process is segmented into multiple independent verification steps: reputation information verification, device presence verification, launchpoint verification, installation information verification, and expected state verification. Each segment checks a specific aspect of the clean file's legitimacy, allowing comprehensive detection without treating the entire file as malware.
Solution Approach 2:
The system performs preliminary verification of clean files before they are executed or used by malware. By checking reputation information, device presence, launchpoint, installation information, and expected state in advance, the system prevents malware from successfully utilizing clean files for malicious purposes.
2Measurement precision
If clean files are monitored for malware usage, then detection accuracy improves, but system complexity increases
Solution Approach 1:
The complex verification process is divided into five manageable verification modules, each handling a specific type of information (reputation, device presence, launchpoint, installation, expected state). This segmentation reduces the perceived complexity by organizing the verification process into discrete, independent tasks.
Solution Approach 2:
The system introduces an intermediary verification mechanism that acts as a mediator between the clean file and the execution environment. This intermediary layer performs multiple checks without requiring the clean file itself to be modified, simplifying the overall system architecture while maintaining high detection accuracy.
3Measurement precision
If multiple verification checks are performed on clean files, then false positives decrease, but processing time increases
Solution Approach 1:
Verification checks are performed preliminarily, before the clean file is executed or utilized by malware. This preliminary action allows the system to identify and block malicious usage before it occurs, reducing false positives during actual operations while maintaining efficient processing through advance validation.
Solution Approach 2:
The verification system uses self-service mechanisms by checking multiple attributes of the clean file (reputation, device presence, launchpoint, installation information, expected state) that are inherently available in the system. This approach reduces processing time by leveraging existing system information rather than requiring extensive external validation.
Data Source
AI summary
There are provided measures for enabling the detection of a malware-usable clean file or, stated differently, the detection of malware using a clean file. Such measures could exemplarily include identifying a vulnerable clean file in a computer system, which does not constitute malware but is vulnerable for usage by malware, checking the vulnerable clean file for its threat of usage by malware, and detecting the vulnerable clean file as malware-usable clean file on the basis of a result of said checking of its threat of usage by malware.


