Cloud Malware Detection via Offline Behavioral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures lack effective methods for real-time detection and prevention of malware, especially in providing zero day/zero hour protection against rapidly evolving threats in cloud-based systems.

Innovation Solution

A cloud-based security system that includes nodes for inline monitoring, a behavioral analysis system for offline analysis of suspicious content, and periodic updates of known malware signatures to enhance malware detection and prevention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If cloud-based malware detection is implemented, then malware detection capability is improved, but response time for zero day threats is insufficient

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidresponse time for zero day threats
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining a cloud-based repository of malware indicators (hashes, signatures, behavioral patterns) that are continuously updated. When malware is detected, the system proactively pushes updates to all cloud nodes before the threat can spread, enabling preventive blocking of zero day threats through pre-configured sandbox environments and indicator propagation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where detection results from any cloud node are immediately communicated back to the central cloud repository and distributed to all other nodes. This real-time feedback loop ensures that when new malware patterns are identified, the entire cloud network learns and adapts simultaneously, reducing response time for zero day threats through continuous information exchange.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive malware analysis is performed, then detection accuracy is improved, but processing speed deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The malware analysis system is segmented into multiple specialized cloud nodes, each responsible for specific analysis tasks such as static analysis, dynamic analysis, sandbox execution, and signature matching. This segmentation allows parallel processing of different malware samples simultaneously, maintaining high detection accuracy while improving overall processing throughput by distributing the analytical workload across multiple specialized components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial analysis actions by first performing quick signature-based detection and only initiating comprehensive behavioral analysis when initial screening indicates potential threats. This tiered approach processes the majority of traffic rapidly through lightweight methods while applying full analytical power only to suspicious cases, thereby maintaining high processing speed for benign traffic while ensuring thorough detection accuracy for potential threats.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9609015B2Systems and methods for dynamic cloud-based malware behavior analysis
Publication Date: 2017.03.28 ZSCALER INC
  • US9609015B2 patent drawing
  • US9609015B2 patent drawing
  • US9609015B2 patent drawing

AI summary

A cloud-based method, a behavioral analysis system, and a cloud-based security system can include a plurality of nodes communicatively coupled to one or more users, wherein the plurality of nodes each perform inline monitoring for one of the one or more users for security comprising malware detection and preclusion; and a behavioral analysis system communicatively coupled to the plurality of nodes, wherein the behavioral analysis system performs offline analysis for any suspicious content from the one or more users which is flagged by the plurality of nodes; wherein the plurality of nodes each comprise a set of known malware signatures for the inline monitoring that is periodically updated by the behavioral analysis system based on the offline analysis for the suspicious content.