Distributed Malware Analysis Sharing Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current host-level malware protection systems are susceptible to various attacks, including zero-day attacks, and face inefficiencies due to complexity in detection methods, which can lead to longer execution times and increased susceptibility to malware.
Innovation Solution
A computer-implemented method involving a distributed malware analysis system where multiple networks share malware analysis results through a master manager console, allowing each network to set sharing policies and apportion costs, thereby minimizing inefficiencies and processing loads.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If host-level malware protection systems use complex detection methods, then detection capability is improved, but execution time increases and susceptibility to malware remains
Solution Approach 1:
The patent combines multiple malware analysis systems across different networks into a unified cloud-based platform. By merging detection resources and sharing analysis results network-wide, the system achieves comprehensive detection capability without requiring each individual host to execute complex detection algorithms, thereby reducing execution time while maintaining high reliability.
Solution Approach 2:
The patent introduces a cloud-based malware analysis platform as an intermediary between hosts and malware threats. Instead of performing complex detection directly on hosts, the system mediates analysis through centralized cloud services that specialize in malware detection, allowing hosts to benefit from expert analysis without bearing the computational burden.
2Reliability
If each network performs independent malware analysis, then detection autonomy is maintained, but processing load and costs increase
Solution Approach 1:
The patent segments malware analysis functions into two parts: lightweight local screening performed autonomously by each network's hosts, and heavy-duty deep analysis performed by the cloud platform. This segmentation allows networks to maintain autonomy for routine detections while leveraging centralized resources for complex cases, optimizing both independence and efficiency.
Solution Approach 2:
The cloud-based malware analysis platform provides universal service to multiple networks simultaneously. A single analysis infrastructure serves diverse networks, allowing them to share processing costs and benefits from collective security intelligence. The platform maintains policy-based autonomy controls to respect each network's specific requirements while achieving economies of scale.
3Productivity
If malware analysis results are shared across networks, then detection efficiency is improved, but information security and cost control become challenging
Solution Approach 1:
The patent implements dynamic, policy-based information sharing controls that adapt to each network's security requirements. Sharing policies are not static but can be adjusted based on trust relationships, threat levels, and organizational preferences. This dynamic approach enables efficient information flow when appropriate while maintaining security boundaries when needed.
Solution Approach 2:
The patent applies different sharing policies to different networks and different types of information. Rather than uniform sharing or non-sharing, the system tailors information disclosure to local needs and security contexts. Each network can specify what types of malware analysis results it is willing to share and with which networks, creating a nuanced information sharing regime that balances efficiency and security.
Data Source
AI summary
In certain embodiments, a computer-implemented method includes accessing information related to a first file determined to satisfy at least one of a plurality of suspected malware conditions. A first of a number of manager consoles may access the information, each manager console being communicatively coupled to a respective network of a number of networks. A request may be generated for a determination of whether the first file comprises malware. The determination may be conducted at a master manager console. Data may be accessed indicating a result, outputted by the master manager console, of the determination of whether the first file comprises malware. A sharing policy may be accessed and used to determine whether the result is sharable with a second one of the manager consoles. If the result is sharable, a message comprising the result may be generated to be sent to the second manager console.


