Evasive Malicious Object Detection via Behavioral Delta Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security devices face challenges in detecting evasive malicious objects that refrain from exhibiting malicious behavior in emulated environments, leading to incorrect determinations and potential transmission to user devices.

Innovation Solution

A security device compares actual behavior information from user devices with test behavior information from a test environment to identify differences, using this comparison to determine if an object is an evasive malicious object.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security device tests an object in an emulated environment, then the device can analyze behavior without risk to users, but evasive malicious objects may refrain from exhibiting malicious behavior in the emulated environment leading to incorrect detection

Engineering Contradiction:
Improvedetection accuracyVSAvoidevasive capability of malicious objects
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the test environment adaptive rather than static. The security device dynamically adjusts the test environment based on detected behaviors - when suspicious activities are identified in the emulated environment, the device transitions to a live environment for further testing. This dynamic adaptation allows the system to overcome evasive malicious objects that detect and avoid exhibiting malicious behavior in static emulated environments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a behavioral comparison mechanism as an intermediary between the emulated environment testing and final detection determination. By comparing behaviors observed in the emulated environment with expected legitimate behaviors, the system can identify discrepancies that indicate evasive malicious objects. This intermediary comparison layer allows the security device to detect threats that simply observing emulated behavior would miss.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a security device uses traditional emulated environment testing, then the device can safely analyze objects, but the detection precision decreases when objects are designed to evade detection in test environments

Engineering Contradiction:
Improvesafety of analysisVSAvoiddetection precision
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent segments the detection process into multiple distinct phases: initial safe testing in an emulated environment, behavioral comparison against legitimacy criteria, and conditional live environment testing. This segmentation allows the system to maintain safety during initial analysis while achieving higher detection precision through progressive refinement. Each segment serves a specific purpose and transitions to the next only when certain conditions are met, preventing premature conclusions about evasive malicious objects.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes key parameters of the testing process based on observed behaviors. When the emulated environment testing reveals suspicious but not conclusive behaviors, the system changes the environment parameter from emulated to live, and adjusts the testing depth and behavioral comparison criteria accordingly. This parameter changing approach allows the system to adapt its detection sensitivity and environmental conditions to match the suspected threat level, improving precision without compromising safety unnecessarily.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If a security device compares behaviors between live and test environments, then the device can identify evasive malicious objects, but the device complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing legitimacy criteria and expected behavior profiles before actual testing occurs. The security device pre-configures the comparison framework, defining what constitutes normal legitimate behavior across different environments. This preliminary preparation simplifies the actual detection process, as the system only needs to compare observed behaviors against pre-defined expectations rather than building complex analysis models in real-time, thereby reducing operational complexity while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3690692B1Identifying an evasive malicious object based on a behavior delta
Publication Date: 2024.02.28 JUNIPER NETWORKS INC
  • EP3690692B1 patent drawingFigure 1
  • EP3690692B1 patent drawingFigure 2
  • EP3690692B1 patent drawingFigure 3

AI summary

A security device may receive actual behavior information associated with an object. The actual behavior information may identify a first set of behaviors associated with executing the object in a live environment. The security device may determine test behavior information associated with the object. The test behavior information may identify a second set of behaviors associated with testing the object in a test environment. The security device may compare the first set of behaviors and the second set of behaviors to determine a difference between the first set of behaviors and the second set of behaviors. The security device may identify whether the object is an evasive malicious object based on the difference between the first set of behaviors and the second set of behaviors. The security device may provide an indication of whether the object is an evasive malicious object.