Emulation Environment Malware Detection via Device Mimicry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware can evade detection in emulation environments by detecting the presence of these environments and altering its behavior accordingly, reducing the effectiveness of automated vetting processes for mobile device software applications.

Innovation Solution

The system enhances the realism of an automated emulation environment by using a device mimic module to control and manipulate the application's view of its execution environment, concealing emulation artifacts and mimicking real-world device properties to prevent malware from detecting the emulation environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If an automated emulation environment is used to vet mobile applications, then the vetting process becomes efficient and scalable, but malware can detect the emulation environment and evade detection by altering its behavior

Engineering Contradiction:
Improvevetting efficiencyVSAvoidmalware detection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a device mimic module as an intermediary between the emulation environment and the malware. This module intercepts and manipulates system calls and environment data to present a realistic device profile to the malware, preventing it from detecting the emulation environment while allowing the vetting process to remain automated and efficient

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of a real mobile device environment within the emulation system. By copying device properties, system behaviors, and environmental characteristics, the emulation environment becomes indistinguishable from a real device, thereby preventing malware from detecting the emulation while maintaining automated vetting capabilities

Inventive Principle:
Principle #26Copying

2Reliability

If a test device isolated from the network is used to load and use the application, then malware cannot evade detection by detecting emulation, but the time and effort required for manual vetting increases significantly

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidvetting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables the emulation environment to automatically present a realistic device profile to the malware without requiring manual intervention. The device mimic module autonomously intercepts and manipulates system calls, and the vetting system automatically analyzes malware behavior, eliminating the need for manual loading and testing while maintaining detection accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of loading applications on isolated test devices with an automated software-based emulation system. The device mimic module software components substitute for physical device manipulation, enabling automatic malware detection while maintaining the isolation and realism needed for accurate detection

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11080399B2System and method for vetting mobile phone software applications
Publication Date: 2021.08.03 THE MITRE CORPORATION
  • US11080399B2 patent drawing
  • US11080399B2 patent drawing
  • US11080399B2 patent drawing

AI summary

A system and method for implementing a software emulation environment is provided. In one example, a mobile application can interface with an emulation environment that can be used to test whether the mobile application includes malware that can compromise the security and integrity of an enterprise's computing infrastructure. When the mobile application issues a call for data, a device mimic module can intercept the call and determine if the call includes a call for one or more checkable artifacts that can reveal the existence of the emulation environment. If such a call for data occurs, the device mimic module can provide one or more spoofed checkable artifacts that have been recorded from a real-world mobile device. In this way, the existence of the emulation environment can be concealed so as to allow for a more thorough analysis of a mobile application for potential hidden malware.