Device Auditing via Physical Memory Modification for Evasive Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for detecting unauthorized programs on devices with limited resources are resource-intensive, power-consuming, and vulnerable to evasion by sophisticated malware, often failing to detect new instances or those intentionally installed to bypass detection.
Innovation Solution
A device auditing process that involves a series of modifications to physical memory, verified by a verifier, to detect and remove evasive programs, using a sequence of modifications that are checked for compliance with expected results, and employing cryptographic techniques to ensure authenticity and detect adversarial strategies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If constant updates and periodic or continuous scans are used to detect unauthorized programs, then detection capability is improved, but resource consumption increases
Solution Approach 1:
The patent implements preliminary action by performing security audits during device boot-up and before critical operations. The system proactively checks for unauthorized programs and modifies to physical memory before they can cause harm, rather than continuously scanning. This approach ensures detection capability while consuming minimal resources during normal operation.
Solution Approach 2:
The system employs periodic action by conducting security scans at specific intervals and triggered events (boot-up, application installation, critical operations). Instead of continuous scanning, the auditor process performs audits periodically or when triggered by specific conditions, reducing resource consumption while maintaining effective detection of unauthorized programs.
2Measurement precision
If detailed logs of device activities are compiled and delivered to central authority, then detection accuracy is improved, but privacy is compromised and resource consumption increases
Solution Approach 1:
The patent extracts only the essential security-relevant information needed for detection, rather than compiling and transmitting detailed logs of all device activities. The auditor process performs local analysis and sends only critical findings or anonymized data to the central authority, maintaining detection accuracy while preserving user privacy and reducing resource consumption for log management.
Solution Approach 2:
The system introduces an intermediary layer (the local auditor process) that analyzes device activities locally and filters information before transmission to the central authority. This intermediary performs preliminary processing and sends only necessary security-related data, reducing privacy loss and resource consumption while maintaining detection accuracy through local intelligence.
3Reliability
If traditional scanning techniques are used, then known malware can be detected, but sophisticated and new malware can evade detection
Solution Approach 1:
The system performs preliminary action by modifying physical memory and executing code in a controlled environment before full system operation. The auditor process makes modifications to physical memory that allow detection of both known malware signatures and behavioral patterns of new/sophisticated malware, enabling proactive identification of threats before they can establish themselves.
Solution Approach 2:
The patent employs parameter changes by dynamically altering system parameters and memory states during auditing. The auditor process changes physical memory parameters and executes operations that reveal the presence of sophisticated malware through behavioral analysis, enabling detection of both signature-based known malware and anomaly-based new threats.
4Duration of action of stationary object
If rootkit evasion techniques are used by malware, then malware persistence is improved, but detection becomes more difficult
Solution Approach 1:
The system converts the harm caused by rootkit evasion techniques into a benefit for detection. By making modifications to physical memory and using controlled environment execution, the auditor process can detect the very alterations and hiding techniques that rootkits employ, turning their persistence mechanisms into detectable anomalies that reveal their presence.
Solution Approach 2:
The auditor process acts as an intermediary between the operating system and the physical hardware, intercepting and analyzing system calls and memory operations. This intermediary position allows it to detect rootkit activities by monitoring the interactions between malware and the system, revealing evasion techniques that would otherwise remain hidden.
Data Source
AI summary
The auditing of a device that includes a physical memory is disclosed. One or more hardware parameters that correspond to a hardware configuration is received. Initialization information is also received. The physical memory is selectively written in accordance with a function. The physical memory is selectively read and at least one result is determined. The result is provided to a verifier.


