External Malware Detection via Virtual Machine Image Copy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware detection tools for smartphones are resource-intensive and less effective due to limited power, processing cycles, and memory, and struggle with advanced malware that evades detection by blocking functions or hiding files, especially in environments like iOS where persistent background tasks are restricted.

Innovation Solution

Capturing a virtual machine image of the smartphone and interrogating it on an external electronic malware detection apparatus, which allows for deep probing and observation without taxing the device's resources, enabling detection of advanced malware and accommodating resource limitations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malware detection tools are run on the smartphone, then malware detection capability is improved, but device resources (power, processing cycles, memory) are consumed

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the malware detection process from the smartphone by creating a virtual machine image of the device and analyzing it externally on a separate system. This separates the detection function from the mobile device, allowing comprehensive malware scanning without consuming the smartphone's limited power, processing, or memory resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a copy of the smartphone's state in the form of a virtual machine image. This copy can be analyzed externally without affecting the original device's operation. The virtual machine image captures files, registry information, and system state, enabling offline malware detection that doesn't impact the living device's resources.

Inventive Principle:
Principle #26Copying

2Reliability

If malware detection tools are run on the smartphone, then malware detection capability is improved, but device responsiveness is reduced

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddevice responsiveness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By extracting the analysis process to an external system using a virtual machine image, the patent eliminates the performance burden from the smartphone. The device can continue operating normally while its image is being analyzed elsewhere, maintaining full responsiveness during detection operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The virtual machine image is created as a preliminary copy that can be analyzed independently. This allows the smartphone to capture its state and then proceed with normal operations while the image undergoes comprehensive malware analysis, separating the detection timeline from device usage.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If deeper probing is performed to detect advanced malware, then detection accuracy is improved, but resource consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts resource-intensive deep probing operations from the smartphone environment to an external analysis system. Advanced malware detection techniques such as memory inspection, behavioral analysis, and deep file system scanning can be performed on the virtual machine image without consuming the mobile device's limited resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The virtual machine image serves as an intermediary that enables deep probing operations. It acts as a bridge between the smartphone and the external analysis system, allowing comprehensive inspection of device state without directly accessing or consuming resources on the live device.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If persistent background tasks are implemented for malware detection, then continuous protection is improved, but compatibility with iOS restrictions is worsened

Engineering Contradiction:
Improvecontinuous protectionVSAvoidoperating system compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the continuous protection function from the iOS device by performing analysis on virtual machine images externally. This bypasses iOS restrictions on persistent background tasks, as the actual detection work occurs on separate systems that don't subject to Apple's sandboxing and background execution limitations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

By working with copies of device state rather than the live device, the system can implement continuous protection through periodic image capture and analysis. Each image represents a snapshot that can be thoroughly analyzed offline, providing continuous monitoring capability without requiring persistent background processes on the iOS device itself.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8904525B1Techniques for detecting malware on a mobile device
Publication Date: 2014.12.02 EMC IP HLDG CO LLC
  • US8904525B1 patent drawing
  • US8904525B1 patent drawing
  • US8904525B1 patent drawing

AI summary

A technique to detect malware on a mobile device which stores a virtual machine image involves establishing a connection from an electronic malware detection apparatus to the mobile device, the electronic malware detection apparatus being external to the mobile device. The technique further involves transferring mobile device data from the mobile device to the electronic malware detection apparatus through the connection to form a copy of the virtual machine image within the electronic malware detection apparatus. The technique further involves performing, by the electronic detection apparatus, a set of malware detection operations on the copy of the virtual machine image to determine whether the mobile device is infected with malware.