Coordinated Endpoint Malware Detection via Security Logic Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional antivirus and malware detection systems are inadequate in detecting advanced, polymorphic malware, leading to false positives and insufficient information about cyber-attacks, which complicates network administrators' ability to identify and respond to potential threats effectively.
Innovation Solution
A coordinated system between network endpoints and a malware detection system, utilizing a security logic engine to combine behavioral monitoring and analysis results from endpoints and the malware detection system, enabling classification of objects as malicious or benign, predicting vulnerable endpoints, and tracing attack paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If conventional antivirus applications use signature-based approach to detect malware, then detection speed is improved, but detection accuracy deteriorates due to inability to detect polymorphic and targeted malware
Solution Approach 1:
The patent combines signature-based detection with behavior-based detection into a unified malware detection system. The system integrates the fast signature matching capability with the accurate behavioral analysis capability, allowing it to maintain detection speed while improving detection accuracy through multiple detection mechanisms working together
Solution Approach 2:
The malware detection system is designed to perform multiple detection functions: signature-based detection for known malware, behavior-based detection for polymorphic and targeted malware, and coordination between endpoint and network detection. This multi-functional approach allows the system to handle diverse malware types effectively
2Measurement precision
If malware detection systems increase analysis capability to detect advanced malware, then detection accuracy is improved, but false positives increase
Solution Approach 1:
The patent implements feedback mechanisms where detection results from multiple sources (endpoint detection, network detection, static analysis, dynamic analysis) are continuously exchanged and refined. The system uses feedback loops to adjust detection thresholds and refine analysis based on corroborating evidence from different detection points, reducing false positives while maintaining high detection accuracy
Solution Approach 2:
The patent introduces coordination mechanisms as intermediaries between different detection systems. The coordination layer acts as a mediator that aggregates evidence from multiple sources before generating final detection results, filtering out false positives through cross-validation and providing a unified view that reduces spurious alerts
3Measurement precision
If network periphery detection systems perform comprehensive analysis, then detection accuracy is improved, but analysis time increases causing delays in preventing network intrusion
Solution Approach 1:
The patent performs preliminary static analysis of network traffic at the network periphery to identify suspicious patterns before allowing dynamic execution analysis. This preliminary screening filters out benign traffic early, reserving comprehensive dynamic analysis only for suspicious cases, thereby reducing overall analysis time while maintaining detection accuracy
Solution Approach 2:
The detection process is segmented into multiple phases: initial signature-based filtering, behavioral analysis phase, and comprehensive dynamic analysis phase. Each phase handles specific types of detection tasks, allowing the system to process most traffic efficiently through lighter phases while reserving resource-intensive comprehensive analysis for cases that require it
4Measurement precision
If multiple malware detection systems are deployed throughout the network, then detection coverage is improved, but system complexity and difficulty of managing security alerts increase
Solution Approach 1:
The patent merges multiple distributed detection systems into a coordinated network where endpoints, network periphery systems, and central management work together. The coordination mechanism consolidates alerts and findings from multiple sources into a unified view, reducing the complexity of managing multiple independent systems while maintaining comprehensive detection coverage
Solution Approach 2:
The malware detection system is designed with universal coordination capabilities that work across different detection points and system types. The coordination layer provides a unified interface and common detection logic that can be applied consistently across the entire network, simplifying management while enabling comprehensive multi-point detection
5Loss of information
If malware detection systems generate detailed security alerts, then information completeness is improved, but actionability deteriorates due to difficulty in identifying high priority alerts among numerous alerts
Solution Approach 1:
The patent implements feedback loops where detection results and alert priorities are continuously refined based on coordination between multiple detection systems. The system uses feedback from corroborating evidence to dynamically adjust alert priorities and filter out low-confidence alerts, maintaining information completeness while improving actionability through evidence-based prioritization
Solution Approach 2:
The coordination mechanism acts as an intermediary that processes and prioritizes alerts from multiple detection systems. It aggregates information from various sources, evaluates the collective evidence, and generates prioritized actionable intelligence that maintains completeness while presenting a manageable view to security personnel
Data Source
AI summary
A system and non-transitory computer-readable medium including security logic engine (SLE) to detect malicious objects based on operations conducted by an endpoint device and/or a malware detection system. The SLE includes formatting logic and a correlation engine. The formatting logic is configured to receive data from an endpoint device and a malware detection system via a network interface and to convert the data into a format used by logic within the SLE. The correlation engine is configured to (i) correlate a plurality of features included as part of the data with known behaviors and characteristics of at least malicious objects and (ii) correlate a first set of features of the plurality of features received from the endpoint device with a second set of features of the plurality of features received from the malware detection system to verify a determination of maliciousness by the endpoint device and/or the malware detection system.


