Endpoint Malware Detection via Segmented Light Analysis and Sandbox Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware detection systems on endpoint devices face performance degradation and interference with other software, requiring resource-intensive monitoring and analysis, which can lead to false positives and disruptions in user experience, and fail to effectively integrate results from both endpoint device analysis and sandbox environments.

Innovation Solution

Implementing a cloud-based malware analysis system using a light analysis tool on endpoint devices for static and dynamic analysis, with a sandbox for deep analysis, and a correlator to combine results and update detection models, allowing for efficient malware detection without performance degradation and integrating findings from both environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep malware analysis is performed on the endpoint device, then detection accuracy is improved, but device performance degrades and user experience is disrupted

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidendpoint device performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The malware analysis system is segmented into two distinct environments: endpoint device analysis for initial detection and sandbox analysis for deep verification. This segmentation allows lightweight analysis on the endpoint while reserving resource-intensive deep analysis for the sandbox environment, thereby maintaining endpoint performance while improving detection accuracy through correlated analysis results.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive malware monitoring is implemented on the endpoint device, then detection capability is improved, but interference with other software increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsoftware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The sandbox serves as an intermediary environment that performs deep malware analysis without directly interfering with endpoint device operations. By transferring suspicious samples to the sandbox for comprehensive analysis and then correlating results back to the endpoint, the system achieves thorough detection capability while minimizing interference with other software running on the endpoint device.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If separate analysis systems are used for endpoint device and sandbox, then analysis depth is improved, but result integration becomes difficult

Engineering Contradiction:
Improveanalysis depthVSAvoidsystem integration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

A feedback mechanism is implemented where sandbox analysis results are correlated with endpoint device analysis results. The system continuously refines detection models by incorporating feedback from both environments, allowing deep sandbox analysis to inform and improve endpoint detection capabilities while maintaining a unified security posture through iterative model updates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11438349B2Systems and methods for protecting devices from malware
Publication Date: 2022.09.06 MIDCAP FINANCIAL TRUST
  • US11438349B2 patent drawing
  • US11438349B2 patent drawing
  • US11438349B2 patent drawing

AI summary

Disclosed herein are systems and method for protecting an endpoint device from malware. In one aspect, an exemplary method comprises performing, by a light analysis tool of the endpoint, a light static analysis of a sample, terminating the process and notifying the user when the process is malware, performing light dynamic analysis when the process is not malware based on the light static analysis, when the process is clean based on the light dynamic analysis, enabling the process to execute, when the process is malware, terminating the process and notifying the user, and when the process is suspicious pattern, suspending the process, setting a level of trust, sending the sample to a sandbox, terminating the process and notifying the user when the process is a malware based on received final verdict, enabling the process to resume executing when the process is determined as being clean based on the final verdict.