Geolocation-Aware Malware Detection via Virtual Environment Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively detect geolocation-aware malware that targets specific geographic locations, as they often rely on geo-IP requests and local artifact analysis to determine execution of malicious payloads, leading to missed detections in non-target locations.

Innovation Solution

The method involves receiving trajectory information for network traffic carrying geolocation-aware malware, identifying the target geolocation characteristic required for activation, establishing an execution environment with those characteristics on a user machine image, running the malware in this environment, and analyzing its functioning to detect malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If malware analysis is performed in a generic execution environment, then the analysis process is simple and fast, but geolocation-aware malware cannot be properly detected because it requires specific geographic characteristics to activate malicious payloads

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary analysis of trajectory information to identify target geolocation characteristics before executing the malware. This advance preparation allows the creation of an appropriately configured execution environment that matches the malware's target location, enabling accurate detection without requiring complex real-time modifications during malware execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a specialized execution environment that acts as an intermediary between the malware and the analysis system. This environment mimics the target geolocation characteristics (such as language settings, time zone, keyboard layout) without requiring the actual physical location, allowing the malware to activate its malicious payload while remaining contained and analyzable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system creates specialized execution environments for each geolocation target, then detection accuracy improves, but the time and resources required for analysis increase

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Instead of analyzing malware in multiple physical locations, the system creates virtual copies of geolocation characteristics within a controlled execution environment. These copies include simulated language settings, time zones, and other location-specific artifacts that trigger the malware's geographic activation logic, enabling accurate detection without time-consuming physical relocation or multiple environment setups.

Inventive Principle:
Principle #26Copying

3Measurement precision

If geolocation-aware malware is analyzed in its target location environment, then malicious activity can be detected, but the risk of actual harm increases

Engineering Contradiction:
Improvemalicious activity detectionVSAvoidpotential damage from malware execution
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent creates an inert or isolated execution environment that mimics the target geolocation characteristics while preventing any actual harmful effects. This controlled environment captures and contains the malware's malicious activities (such as data exfiltration attempts, system modifications, or network communications) without allowing them to cause real damage to production systems or networks, enabling safe analysis of geolocation-triggered payloads.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

Data Source

PatentUS10771482B1Systems and methods for detecting geolocation-aware malware
Publication Date: 2020.09.08 CA TECH INC
  • US10771482B1 patent drawing
  • US10771482B1 patent drawing
  • US10771482B1 patent drawing

AI summary

The disclosed computer-implemented method for detecting geolocation-aware malware may include (1) receiving, by a computing device, trajectory information for network traffic carrying geolocation-aware malware, (2) identifying, from the trajectory information, a target geolocation characteristic required to activate the geolocation-aware malware, (3) establishing, on an image of a user machine, an execution environment having the target geolocation characteristic, (4) running, on the image of the user machine, the geolocation-aware malware, and (5) analyzing functioning of the geolocation-aware malware to identify malicious activity by the geolocation-aware malware. Various other methods, systems, and computer-readable media are also disclosed.