Cloud Malware Detection via Behavioral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures lack effective methods for dynamic detection and prevention of malware, particularly in providing zero day/zero hour protection against rapidly evolving threats in cloud-based systems.

Innovation Solution

A cloud-based security system that includes nodes for inline monitoring and a behavioral analysis system for offline analysis of suspicious content, using static and dynamic analysis to determine malware and update known signatures for immediate protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud-based malware detection is implemented, then malware detection capability is improved, but response time for zero day threats is insufficient

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidresponse time for zero day threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining a cloud-based repository of malware behaviors and characteristics before zero day threats emerge. When new malware is detected, the system has pre-established frameworks and algorithms ready to rapidly analyze and classify the threat, eliminating the need to build detection capabilities from scratch and enabling near-immediate response to zero day threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where malware detection results, behavioral analysis data, and threat intelligence are constantly fed back into the cloud-based repository. This feedback mechanism allows the system to learn from each detected threat and rapidly update its detection algorithms, ensuring that zero day threats are identified and classified quickly through iterative analysis and adaptation.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive malware analysis is performed, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the comprehensive malware analysis process into distinct modular components: initial detection at network nodes, behavioral analysis in sandbox environments, classification algorithms in the cloud, and signature generation. Each segment handles a specific aspect of analysis, allowing complex detection tasks to be distributed across multiple specialized modules rather than requiring a single monolithic system, thus maintaining high accuracy while managing complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cloud-based platform serves as an intermediary that coordinates between various analysis components including sandbox environments, behavioral analysis engines, and signature databases. This intermediary layer manages the complexity by providing a unified interface and orchestration mechanism, allowing comprehensive analysis to be performed without requiring direct integration and management of all individual components at each network node.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If distributed cloud-based system is used, then detection speed is improved, but infrastructure requirements increase

Engineering Contradiction:
Improvemalware detection speedVSAvoidinfrastructure requirements
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system merges the computational resources, storage capacity, and analytical capabilities of multiple distributed cloud nodes into a unified malware detection infrastructure. By combining resources across the cloud network, the system achieves high-speed parallel processing of malware samples and rapid dissemination of detection results to all nodes, improving overall detection speed while sharing the infrastructure burden across the distributed system rather than requiring each individual node to have full capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9152789B2Systems and methods for dynamic cloud-based malware behavior analysis
Publication Date: 2015.10.06 ZSCALER INC
  • US9152789B2 patent drawing
  • US9152789B2 patent drawing
  • US9152789B2 patent drawing

AI summary

A cloud-based method, a behavioral analysis system, and a cloud-based security system can include a plurality of nodes communicatively coupled to one or more users, wherein the plurality of nodes each perform inline monitoring for one of the one or more users for security comprising malware detection and preclusion; and a behavioral analysis system communicatively coupled to the plurality of nodes, wherein the behavioral analysis system performs offline analysis for any suspicious content from the one or more users which is flagged by the plurality of nodes; wherein the plurality of nodes each comprise a set of known malware signatures for the inline monitoring that is periodically updated by the behavioral analysis system based on the offline analysis for the suspicious content.