Electronic Crime Detection via Malware De-compilation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods focus primarily on combating the credential collection phase of electronic crime, neglecting the monetization and laundering phases, which are crucial for disrupting the economic incentives driving electronic crime, and lack a comprehensive approach to track and prosecute electronic criminals across the entire business process.
Innovation Solution
A system and method that includes a computer system, database, malware de-compiler, parser, and inference engine to analyze electronic crime attack signatures, identify individuals and locations involved in the monetization and laundering phases, and provide actionable intelligence to law enforcement and financial institutions to intervene and disrupt the electronic crime business process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If current methods focus primarily on combating the credential collection phase, then the detection capability for credential theft is improved, but the overall effectiveness in disrupting electronic crime business processes deteriorates
Solution Approach 1:
The patent segments the electronic crime business process into three distinct phases (credential collection, monetization, and laundering) and applies specialized detection methods to each phase. This segmentation allows the system to maintain high detection precision for credential theft while simultaneously improving overall effectiveness by comprehensively tracking all phases of the crime process through separate but integrated analysis streams.
Solution Approach 2:
The system creates a multi-functional framework that can detect and analyze all three phases of electronic crime through a unified platform. The database and analysis methods are designed to handle diverse crime types across different phases, making the system universally applicable while maintaining specialized detection capabilities for each phase.
2Reliability
If a comprehensive approach to track and prosecute electronic criminals across the entire business process is implemented, then the overall prosecution effectiveness is improved, but the system complexity increases
Solution Approach 1:
The patent divides the complex prosecution process into three manageable segments corresponding to the three crime phases. Each segment has its own analysis methods and database structures, which reduces the complexity of implementing a comprehensive system while maintaining overall effectiveness. The segmented approach allows incremental implementation and easier maintenance.
Solution Approach 2:
The patent introduces a centralized database as an intermediary that connects and coordinates the analysis of all three crime phases. This intermediary structure simplifies the overall system by providing a single point of integration, allowing complex multi-phase tracking to be managed through a unified data repository rather than requiring direct complex interactions between all analysis components.
3Reliability
If the monetization and laundering phases are targeted, then the economic incentives for electronic crime are disrupted, but the difficulty of detecting and measuring these phases increases
Solution Approach 1:
The patent replaces traditional mechanical investigation methods with automated computational analysis for detecting monetization and laundering phases. By using algorithmic pattern recognition and data analysis instead of manual investigation, the system can handle the complexity of these phases while maintaining detection capability. This substitution enables effective targeting of economic incentive phases without proportionally increasing detection difficulty.
Solution Approach 2:
The patent creates digital copies and representations of crime patterns across all phases, including monetization and laundering. By analyzing copied data representations rather than raw complex transactions, the system can effectively detect and measure these difficult phases while maintaining the ability to disrupt economic incentives through identified patterns.
Data Source
AI summary
A system for electronic crime reduction is provided, comprising a computer system, a database, a malware de-compiler, a malware parser, and an inference engine. The database contains information that associates electronic crime attack signature data with at least one of an individual, a group, and a location. The malware de-compiler, when executed on the computer system, translates a first malware executable to an assembly language version. The first malware is associated with an electronic crime that has been committed. The malware parser, when executed on the computer system, analyzes the assembly language version to identify distinctive coding preferences used to develop the first malware. The inference engine, when executed on the computer system, analyzes the distinctive coding preferences identified by the malware parser application in combination with searching the database to identify one of an individual, a group, and a location associated with the electronic crime.


