Coordinated Endpoint Malware Detection via Security Logic Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional antivirus and malware detection systems are inadequate in detecting advanced, polymorphic malware, leading to false positives and insufficient information about cyber-attacks, which complicates network administrators' ability to identify and respond to potential threats effectively.

Innovation Solution

A coordinated system between network endpoints and a malware detection system, utilizing a security logic engine to combine behavioral monitoring and analysis results from endpoints and the malware detection system, enabling classification of objects as malicious or benign, predicting vulnerable endpoints, and tracing attack paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If conventional antivirus applications use signature-based approach to detect malware, then detection speed is improved, but detection accuracy deteriorates due to inability to detect polymorphic and targeted malware

Engineering Contradiction:
Improvedetection speedVSAvoiddetection accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent combines signature-based detection with behavior-based detection into a unified malware detection system. The system integrates the fast signature matching capability with the accurate behavioral analysis capability, allowing it to maintain detection speed while improving detection accuracy through multiple detection mechanisms working together

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The malware detection system is designed to perform multiple detection functions: signature-based detection for known malware, behavior-based detection for polymorphic and targeted malware, and coordination between endpoint and network detection. This multi-functional approach allows the system to handle diverse malware types effectively

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If malware detection systems increase analysis capability to detect advanced malware, then detection accuracy is improved, but false positives increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positives
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where detection results from multiple sources (endpoint detection, network detection, static analysis, dynamic analysis) are continuously exchanged and refined. The system uses feedback loops to adjust detection thresholds and refine analysis based on corroborating evidence from different detection points, reducing false positives while maintaining high detection accuracy

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces coordination mechanisms as intermediaries between different detection systems. The coordination layer acts as a mediator that aggregates evidence from multiple sources before generating final detection results, filtering out false positives through cross-validation and providing a unified view that reduces spurious alerts

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If network periphery detection systems perform comprehensive analysis, then detection accuracy is improved, but analysis time increases causing delays in preventing network intrusion

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary static analysis of network traffic at the network periphery to identify suspicious patterns before allowing dynamic execution analysis. This preliminary screening filters out benign traffic early, reserving comprehensive dynamic analysis only for suspicious cases, thereby reducing overall analysis time while maintaining detection accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The detection process is segmented into multiple phases: initial signature-based filtering, behavioral analysis phase, and comprehensive dynamic analysis phase. Each phase handles specific types of detection tasks, allowing the system to process most traffic efficiently through lighter phases while reserving resource-intensive comprehensive analysis for cases that require it

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If multiple malware detection systems are deployed throughout the network, then detection coverage is improved, but system complexity and difficulty of managing security alerts increase

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple distributed detection systems into a coordinated network where endpoints, network periphery systems, and central management work together. The coordination mechanism consolidates alerts and findings from multiple sources into a unified view, reducing the complexity of managing multiple independent systems while maintaining comprehensive detection coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The malware detection system is designed with universal coordination capabilities that work across different detection points and system types. The coordination layer provides a unified interface and common detection logic that can be applied consistently across the entire network, simplifying management while enabling comprehensive multi-point detection

Inventive Principle:
Principle #6Universality (Multi-functionality)

5Loss of information

If malware detection systems generate detailed security alerts, then information completeness is improved, but actionability deteriorates due to difficulty in identifying high priority alerts among numerous alerts

Engineering Contradiction:
Improveinformation completenessVSAvoidalert actionability
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent implements feedback loops where detection results and alert priorities are continuously refined based on coordination between multiple detection systems. The system uses feedback from corroborating evidence to dynamically adjust alert priorities and filter out low-confidence alerts, maintaining information completeness while improving actionability through evidence-based prioritization

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The coordination mechanism acts as an intermediary that processes and prioritizes alerts from multiple detection systems. It aggregates information from various sources, evaluates the collective evidence, and generates prioritized actionable intelligence that maintains completeness while presenting a manageable view to security personnel

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12166786B1Malware detection verification and enhancement by coordinating endpoint and malware detection systems
Publication Date: 2024.12.10 MAGENTA SECURITY HOLDINGS LLC
  • US12166786B1 patent drawing
  • US12166786B1 patent drawing
  • US12166786B1 patent drawing

AI summary

A system and non-transitory computer-readable medium including security logic engine (SLE) to detect malicious objects based on operations conducted by an endpoint device and/or a malware detection system. The SLE includes formatting logic and a correlation engine. The formatting logic is configured to receive data from an endpoint device and a malware detection system via a network interface and to convert the data into a format used by logic within the SLE. The correlation engine is configured to (i) correlate a plurality of features included as part of the data with known behaviors and characteristics of at least malicious objects and (ii) correlate a first set of features of the plurality of features received from the endpoint device with a second set of features of the plurality of features received from the malware detection system to verify a determination of maliciousness by the endpoint device and/or the malware detection system.