Emulation Environment Malware Detection via Device Mimicry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malware can evade detection in emulation environments by detecting the presence of these environments and altering its behavior accordingly, reducing the effectiveness of automated vetting processes for mobile device software applications.
Innovation Solution
The system enhances the realism of an automated emulation environment by using a device mimic module to control and manipulate the application's view of its execution environment, concealing emulation artifacts and mimicking real-world device properties to prevent malware from detecting the emulation environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If an automated emulation environment is used to vet mobile applications, then the vetting process becomes efficient and scalable, but malware can detect the emulation environment and evade detection by altering its behavior
Solution Approach 1:
The patent introduces a device mimic module as an intermediary between the emulation environment and the malware. This module intercepts and manipulates system calls and environment data to present a realistic device profile to the malware, preventing it from detecting the emulation environment while allowing the vetting process to remain automated and efficient
Solution Approach 2:
The patent creates a virtual copy of a real mobile device environment within the emulation system. By copying device properties, system behaviors, and environmental characteristics, the emulation environment becomes indistinguishable from a real device, thereby preventing malware from detecting the emulation while maintaining automated vetting capabilities
2Reliability
If a test device isolated from the network is used to load and use the application, then malware cannot evade detection by detecting emulation, but the time and effort required for manual vetting increases significantly
Solution Approach 1:
The patent enables the emulation environment to automatically present a realistic device profile to the malware without requiring manual intervention. The device mimic module autonomously intercepts and manipulates system calls, and the vetting system automatically analyzes malware behavior, eliminating the need for manual loading and testing while maintaining detection accuracy
Solution Approach 2:
The patent replaces the manual mechanical process of loading applications on isolated test devices with an automated software-based emulation system. The device mimic module software components substitute for physical device manipulation, enabling automatic malware detection while maintaining the isolation and realism needed for accurate detection
Data Source
AI summary
A system and method for implementing a software emulation environment is provided. In one example, a mobile application can interface with an emulation environment that can be used to test whether the mobile application includes malware that can compromise the security and integrity of an enterprise's computing infrastructure. When the mobile application issues a call for data, a device mimic module can intercept the call and determine if the call includes a call for one or more checkable artifacts that can reveal the existence of the emulation environment. If such a call for data occurs, the device mimic module can provide one or more spoofed checkable artifacts that have been recorded from a real-world mobile device. In this way, the existence of the emulation environment can be concealed so as to allow for a more thorough analysis of a mobile application for potential hidden malware.


