Cooperative Anti-Malware Detection for Stealth Polymorphic Infections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-malware systems struggle to detect stealthy polymorphic malware infections that evade traditional detection methods, leading to widespread compromises within networks, as these infections can go undetected until defenses are breached.

Innovation Solution

A system and method that cooperatively detect system attacks by identifying the origin of attacks from compromised systems, confirming the presence of anti-malware agents, and notifying these agents to remediate the infections, even when malware employs stealth features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional scanning methods are used to detect malware, then the detection process is simple and fast, but polymorphic malware with stealth features can evade detection

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple detection systems into a coordinated network. A first anti-malware system on the compromised system works together with a second anti-malware system on a remote system, sharing detection capabilities and information to overcome the limitations of individual systems and detect stealthy polymorphic malware more reliably

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a network as an intermediary that connects multiple anti-malware systems. This intermediary enables communication and coordination between the first and second anti-malware systems, allowing them to share detection data and cooperate to identify malware that would evade isolated detection methods

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If anti-malware agents are deployed on all systems, then detection coverage is improved, but the complexity of managing and coordinating multiple agents increases

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem coordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the anti-malware detection function into separate segments deployed on different systems. The first anti-malware agent runs locally on the compromised system while the second agent runs on a remote system, allowing each segment to operate independently yet contribute to overall detection coverage through networked coordination

Inventive Principle:
Principle #1Segmentation

3Reliability

If cooperative anti-malware systems are implemented, then stealth malware detection is improved, but the time and resources required for coordination increase

Engineering Contradiction:
Improvestealth malware detectionVSAvoiddetection and coordination time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary actions by having anti-malware agents continuously monitor and prepare detection capabilities in advance. The systems pre-establish communication channels and detection protocols, so when stealth malware appears, the coordinated response can occur quickly without requiring time-consuming setup or configuration during the actual detection event

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10721267B1Systems and methods for detecting system attacks
Publication Date: 2020.07.21 GEN DIGITAL INC
  • US10721267B1 patent drawing
  • US10721267B1 patent drawing
  • US10721267B1 patent drawing

AI summary

The disclosed computer-implemented method for detecting system attacks may include (1) receiving, from a detecting system capable of detecting attacks, information that identifies an attack that originated from a compromised client system that is remote from the detecting system, (2) determining that the attack originated from the compromised client system, (3) determining that the compromised client system includes an anti-malware agent, and (4) notifying the anti-malware agent on the compromised client system that the compromised client system performed the attack. Various other methods, systems, and computer-readable media are also disclosed.