Electronic Crime Detection via Malware De-compilation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods focus primarily on combating the credential collection phase of electronic crime, neglecting the monetization and laundering phases, which are crucial for disrupting the economic incentives driving electronic crime, and lack a comprehensive approach to track and prosecute electronic criminals across the entire business process.

Innovation Solution

A system and method that includes a computer system, database, malware de-compiler, parser, and inference engine to analyze electronic crime attack signatures, identify individuals and locations involved in the monetization and laundering phases, and provide actionable intelligence to law enforcement and financial institutions to intervene and disrupt the electronic crime business process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current methods focus primarily on combating the credential collection phase, then the detection capability for credential theft is improved, but the overall effectiveness in disrupting electronic crime business processes deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidoverall effectiveness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the electronic crime business process into three distinct phases (credential collection, monetization, and laundering) and applies specialized detection methods to each phase. This segmentation allows the system to maintain high detection precision for credential theft while simultaneously improving overall effectiveness by comprehensively tracking all phases of the crime process through separate but integrated analysis streams.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a multi-functional framework that can detect and analyze all three phases of electronic crime through a unified platform. The database and analysis methods are designed to handle diverse crime types across different phases, making the system universally applicable while maintaining specialized detection capabilities for each phase.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a comprehensive approach to track and prosecute electronic criminals across the entire business process is implemented, then the overall prosecution effectiveness is improved, but the system complexity increases

Engineering Contradiction:
Improveprosecution effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the complex prosecution process into three manageable segments corresponding to the three crime phases. Each segment has its own analysis methods and database structures, which reduces the complexity of implementing a comprehensive system while maintaining overall effectiveness. The segmented approach allows incremental implementation and easier maintenance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized database as an intermediary that connects and coordinates the analysis of all three crime phases. This intermediary structure simplifies the overall system by providing a single point of integration, allowing complex multi-phase tracking to be managed through a unified data repository rather than requiring direct complex interactions between all analysis components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the monetization and laundering phases are targeted, then the economic incentives for electronic crime are disrupted, but the difficulty of detecting and measuring these phases increases

Engineering Contradiction:
Improvecrime disruption effectivenessVSAvoiddetection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent replaces traditional mechanical investigation methods with automated computational analysis for detecting monetization and laundering phases. By using algorithmic pattern recognition and data analysis instead of manual investigation, the system can handle the complexity of these phases while maintaining detection capability. This substitution enables effective targeting of economic incentive phases without proportionally increasing detection difficulty.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates digital copies and representations of crime patterns across all phases, including monetization and laundering. By analyzing copied data representations rather than raw complex transactions, the system can effectively detect and measure these difficult phases while maintaining the ability to disrupt economic incentives through identified patterns.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9904955B2Electronic crime detection and tracking
Publication Date: 2018.02.27 GOOGLE LLC
  • US9904955B2 patent drawing
  • US9904955B2 patent drawing
  • US9904955B2 patent drawing

AI summary

A system for electronic crime reduction is provided, comprising a computer system, a database, a malware de-compiler, a malware parser, and an inference engine. The database contains information that associates electronic crime attack signature data with at least one of an individual, a group, and a location. The malware de-compiler, when executed on the computer system, translates a first malware executable to an assembly language version. The first malware is associated with an electronic crime that has been committed. The malware parser, when executed on the computer system, analyzes the assembly language version to identify distinctive coding preferences used to develop the first malware. The inference engine, when executed on the computer system, analyzes the distinctive coding preferences identified by the malware parser application in combination with searching the database to identify one of an individual, a group, and a location associated with the electronic crime.