Device Auditing via Physical Memory Modification for Evasive Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for detecting unauthorized programs on devices with limited resources are resource-intensive, power-consuming, and vulnerable to evasion by sophisticated malware, often failing to detect new instances or those intentionally installed to bypass detection.

Innovation Solution

A device auditing process that involves a series of modifications to physical memory, verified by a verifier, to detect and remove evasive programs, using a sequence of modifications that are checked for compliance with expected results, and employing cryptographic techniques to ensure authenticity and detect adversarial strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If constant updates and periodic or continuous scans are used to detect unauthorized programs, then detection capability is improved, but resource consumption increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by performing security audits during device boot-up and before critical operations. The system proactively checks for unauthorized programs and modifies to physical memory before they can cause harm, rather than continuously scanning. This approach ensures detection capability while consuming minimal resources during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs periodic action by conducting security scans at specific intervals and triggered events (boot-up, application installation, critical operations). Instead of continuous scanning, the auditor process performs audits periodically or when triggered by specific conditions, reducing resource consumption while maintaining effective detection of unauthorized programs.

Inventive Principle:
Principle #19Periodic action

2Measurement precision

If detailed logs of device activities are compiled and delivered to central authority, then detection accuracy is improved, but privacy is compromised and resource consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprivacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts only the essential security-relevant information needed for detection, rather than compiling and transmitting detailed logs of all device activities. The auditor process performs local analysis and sends only critical findings or anonymized data to the central authority, maintaining detection accuracy while preserving user privacy and reducing resource consumption for log management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces an intermediary layer (the local auditor process) that analyzes device activities locally and filters information before transmission to the central authority. This intermediary performs preliminary processing and sends only necessary security-related data, reducing privacy loss and resource consumption while maintaining detection accuracy through local intelligence.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional scanning techniques are used, then known malware can be detected, but sophisticated and new malware can evade detection

Engineering Contradiction:
Improvedetection of known malwareVSAvoiddetection of new and sophisticated malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by modifying physical memory and executing code in a controlled environment before full system operation. The auditor process makes modifications to physical memory that allow detection of both known malware signatures and behavioral patterns of new/sophisticated malware, enabling proactive identification of threats before they can establish themselves.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs parameter changes by dynamically altering system parameters and memory states during auditing. The auditor process changes physical memory parameters and executes operations that reveal the presence of sophisticated malware through behavioral analysis, enabling detection of both signature-based known malware and anomaly-based new threats.

Inventive Principle:
Principle #35Parameter changes

4Duration of action of stationary object

If rootkit evasion techniques are used by malware, then malware persistence is improved, but detection becomes more difficult

Engineering Contradiction:
Improvemalware persistenceVSAvoiddetection difficulty
Core Design Contradiction:
Duration of action of stationary objectVSDifficulty of detecting and measuring

Solution Approach 1:

The system converts the harm caused by rootkit evasion techniques into a benefit for detection. By making modifications to physical memory and using controlled environment execution, the auditor process can detect the very alterations and hiding techniques that rootkits employ, turning their persistence mechanisms into detectable anomalies that reveal their presence.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The auditor process acts as an intermediary between the operating system and the physical hardware, intercepting and analyzing system calls and memory operations. This intermediary position allows it to detect rootkit activities by monitoring the interactions between malware and the system, revealing evasion techniques that would otherwise remain hidden.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8370935B1Auditing a device
Publication Date: 2013.02.05 QUALCOMM INC
  • US8370935B1 patent drawing
  • US8370935B1 patent drawing
  • US8370935B1 patent drawing

AI summary

The auditing of a device that includes a physical memory is disclosed. One or more hardware parameters that correspond to a hardware configuration is received. Initialization information is also received. The physical memory is selectively written in accordance with a function. The physical memory is selectively read and at least one result is determined. The result is provided to a verifier.