Endpoint Malware Detection via Segmented Light Analysis and Sandbox Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware detection systems on endpoint devices face performance degradation and interference with other software, requiring resource-intensive monitoring and analysis, which can lead to false positives and disruptions in user experience, and fail to effectively integrate results from both endpoint device analysis and sandbox environments.
Innovation Solution
Implementing a cloud-based malware analysis system using a light analysis tool on endpoint devices for static and dynamic analysis, with a sandbox for deep analysis, and a correlator to combine results and update detection models, allowing for efficient malware detection without performance degradation and integrating findings from both environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep malware analysis is performed on the endpoint device, then detection accuracy is improved, but device performance degrades and user experience is disrupted
Solution Approach 1:
The malware analysis system is segmented into two distinct environments: endpoint device analysis for initial detection and sandbox analysis for deep verification. This segmentation allows lightweight analysis on the endpoint while reserving resource-intensive deep analysis for the sandbox environment, thereby maintaining endpoint performance while improving detection accuracy through correlated analysis results.
2Reliability
If comprehensive malware monitoring is implemented on the endpoint device, then detection capability is improved, but interference with other software increases
Solution Approach 1:
The sandbox serves as an intermediary environment that performs deep malware analysis without directly interfering with endpoint device operations. By transferring suspicious samples to the sandbox for comprehensive analysis and then correlating results back to the endpoint, the system achieves thorough detection capability while minimizing interference with other software running on the endpoint device.
3Measurement precision
If separate analysis systems are used for endpoint device and sandbox, then analysis depth is improved, but result integration becomes difficult
Solution Approach 1:
A feedback mechanism is implemented where sandbox analysis results are correlated with endpoint device analysis results. The system continuously refines detection models by incorporating feedback from both environments, allowing deep sandbox analysis to inform and improve endpoint detection capabilities while maintaining a unified security posture through iterative model updates.
Data Source
AI summary
Disclosed herein are systems and method for protecting an endpoint device from malware. In one aspect, an exemplary method comprises performing, by a light analysis tool of the endpoint, a light static analysis of a sample, terminating the process and notifying the user when the process is malware, performing light dynamic analysis when the process is not malware based on the light static analysis, when the process is clean based on the light dynamic analysis, enabling the process to execute, when the process is malware, terminating the process and notifying the user, and when the process is suspicious pattern, suspending the process, setting a level of trust, sending the sample to a sandbox, terminating the process and notifying the user when the process is a malware based on received final verdict, enabling the process to resume executing when the process is determined as being clean based on the final verdict.


