Context-Aware Malware Detection via Simulated User Interaction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware detection systems face challenges in detecting malicious software due to sophisticated self-defense mechanisms that prevent activation in virtual environments, leading to high false negatives and increased false positives, as they rely on static simulated input device controls that can be identified and evaded by malware creators.

Innovation Solution

A malware detection system employing dynamic user interaction control logic within a virtual run-time environment, which includes a profile selector and UI framework to provide context-aware, simulated user interactions tailored to the type of object being processed, using active, passive, and device control simulation logic to detonate and detect malicious objects without user assistance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If generic static patterns of simulated input device controls are used in malware detection, then the system can operate automatically without user interaction, but malware can identify these patterns and refrain from activating malicious code, leading to high false negatives

Engineering Contradiction:
Improveautomatic malware detectionVSAvoidmalware detection accuracy
Core Design Contradiction:
Extent of automationVSMeasurement precision

Solution Approach 1:

The patent applies dynamics by transitioning from static simulated input patterns to dynamic user interaction simulation. The system now adapts its interaction patterns based on the specific object being analyzed, the type of application involved, and real-time observations of the virtual environment. This dynamic approach prevents malware from predicting or identifying the simulation patterns, thereby improving detection accuracy while maintaining automation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters of the simulated user interaction based on contextual information about the object being analyzed. Different interaction patterns, timing, and sequences are applied depending on the object type, application context, and observed system state. This parameter adaptation makes the simulation more realistic and harder for malware to detect and evade.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple pattern detection schemes are deployed to reduce false negatives, then malware detection coverage increases, but the rate of false positives increases

Engineering Contradiction:
Improvemalware detection coverageVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system implements feedback mechanisms where the simulated user interactions observe the responses of the analyzed object and adjust subsequent interactions accordingly. This closed-loop approach allows the system to learn from the object's behavior patterns, distinguish between legitimate and malicious responses, and reduce false positives while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The detection process is segmented into multiple phases with different interaction strategies. Rather than applying a single comprehensive pattern detection scheme, the system divides the analysis into stages, using different simulation patterns appropriate for each phase, thereby reducing the overall false positive rate while maintaining detection effectiveness.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If user interaction is required to activate malicious content in objects, then malware can be detected through observation of malicious behavior, but the system cannot provide necessary user input, causing malware to hibernate and remain undetected

Engineering Contradiction:
Improvemalware activation detectionVSAvoiduser assistance requirement
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system applies self-service by automatically providing the user interactions needed to activate and analyze malicious content. The simulated user interaction component autonomously performs clicks, keystrokes, and other inputs required to trigger malware activation, eliminating the need for human operators while enabling comprehensive malware behavior observation and detection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10798121B1Intelligent context aware user interaction for malware detection
Publication Date: 2020.10.06 MAGENTA SECURITY HOLDINGS LLC
  • US10798121B1 patent drawing
  • US10798121B1 patent drawing
  • US10798121B1 patent drawing

AI summary

According to one embodiment, a malware detection system is integrated with at least a static analysis engine and a dynamic analysis engine. The static analysis engine is configured to automatically determine an object type of a received object. The dynamic analysis engine is configured to automatically launch the object after selecting an action profile based on the object type. The dynamic analysis engine is further configured to, provide simulated user interaction to the object based on the selected action profile either in response to detecting a request for human interaction or as a result of a lapse of time since a previous simulated human interaction was provided.