Distributed Malware Detection via Federated Neural Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized sandboxing systems for malware detection require significant resources and can be bottlenecked, failing to detect advanced malware that masks its behavior as legitimate processes, and are resource-intensive, making them inefficient for widespread implementation.
Innovation Solution
A decentralized approach using locally trained and federated neural networks to detect malicious processes by examining telemetry data, reducing resource requirements and enabling detection of advanced malware by aggregating results from multiple instances, allowing for distributed processing and quick adaptation to new patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized sandboxing is used for malware detection, then detection capability is improved, but resource consumption increases significantly
Solution Approach 1:
The patent divides the centralized sandboxing system into multiple distributed sandbox instances deployed across different hosts. Each instance independently analyzes unknown files and processes, eliminating the single-point resource bottleneck while maintaining collective detection capability through distributed parallel processing.
Solution Approach 2:
The patent combines the computational resources of multiple hosts to create a federated sandboxing network. By merging detection capabilities across distributed instances and aggregating their results, the system achieves enhanced malware detection while distributing the resource burden across the network rather than concentrating it in one central system.
2Reliability
If centralized sandboxing is used for malware detection, then detection capability is improved, but system bottleneck occurs
Solution Approach 1:
The patent segments the centralized detection function into multiple distributed sandbox instances that operate in parallel across the network. This segmentation eliminates the single-point processing bottleneck by allowing simultaneous analysis of multiple unknown files across different hosts, thereby increasing overall system throughput.
Solution Approach 2:
The patent transitions from a single-dimensional centralized processing model to a multi-dimensional distributed architecture. By adding the dimension of spatial distribution across multiple hosts and introducing federated learning for collaborative intelligence, the system achieves higher processing throughput while maintaining detection accuracy.
3Reliability
If centralized sandboxing is used, then malware analysis capability is improved, but advanced malware can detect and mask its behavior
Solution Approach 1:
The patent implements local sandbox instances with potentially different configurations and environments across the distributed network. This local quality variation prevents advanced malware from easily detecting and adapting to a single centralized analysis pattern, as each local instance presents unique characteristics that make behavioral masking more difficult.
Solution Approach 2:
The patent incorporates federated learning mechanisms where sandbox instances share detection insights and behavioral patterns across the network. This feedback loop enables the distributed system to collectively learn from detected malware behaviors and improve detection capabilities over time, making it harder for advanced malware to evade detection through masking techniques.
Data Source
AI summary
Aspects of the present invention disclose a method, computer program product, and system for detecting a malicious process by a selected instance of an anti-malware system. The method includes one or more processors examining a process for indicators of compromise to the process. The method further includes one or more processors determining a categorization of the process based upon a result of the examination. In response to determining that the categorization of the process does not correspond to a known benevolent process and a known malicious process, the method further includes one or more processors executing the process in a secure enclave. The method further includes one or more processors collecting telemetry data from executing the process in the secure enclave. The method further includes one or more processors passing the collected telemetry data to a locally trained neural network system.


