Endpoint Simulated Security Environment for Malware Execution Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems are unable to guarantee absolute protection from malware and Advanced Persistent Threats (APT) attacks due to malware evasion techniques that prevent detection and execution avoidance, allowing malware to spread within networks and cause significant damage.

Innovation Solution

The implementation of simulated environments on endpoints that mimic security systems, causing malware to refrain from executing without detection, thereby preventing network damage without the need for malware detection through signature analysis or behavior monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malware uses evasion techniques to avoid detection, then malware can execute undetected on endpoints, but security systems cannot detect and analyze the malware

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoidevasion technique complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of trying to detect malware through traditional signature analysis and behavior monitoring, the system inverts the approach by having endpoints simulate security system environments. This causes malware to self-restrain from executing, effectively preventing attacks without requiring detection of the malware's malicious nature.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces an intermediary component - a simulated security system environment deployed on endpoints. This intermediary tricks malware into believing it is running in a secure analysis environment, causing the malware to refrain from execution without actual detection or analysis being performed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security systems analyze malware signatures and behavior, then known threats can be detected, but malware can use evasion techniques to prevent accurate analysis

Engineering Contradiction:
Improvemalware analysis precisionVSAvoidevasion technique impact
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary action by deploying simulated security environments on endpoints before malware can execute. This preemptive measure causes malware to self-restrain from running in the first place, eliminating the need for actual malware analysis and rendering evasion techniques ineffective.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by creating environments that pre-emptively counter malware execution. The simulated security systems prepare the endpoint environments in advance to trick malware into believing it is under observation, causing malware to refrain from executing malicious actions before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If malware detects the presence of security systems, then malware refrains from execution to avoid detection, but malware can still spread to endpoints without security systems present

Engineering Contradiction:
Improvenetwork security reliabilityVSAvoidnetwork operation productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The simulated security system environment is universally deployed across all endpoints in the network, providing multi-functional protection. Each endpoint independently simulates a security environment, creating network-wide protection without requiring centralized detection or analysis capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10230757B2Method and system for handling malware
Publication Date: 2019.03.12 MINERVA LABS
  • US10230757B2 patent drawing
  • US10230757B2 patent drawing
  • US10230757B2 patent drawing

AI summary

Systems, methods, and software products prevent malware attacks on networks, which include endpoint devices, by providing an environment to the endpoint device which simulates an environment, for example, a security environment, where malware is known to refrain from executing.