Honeypot Workflow for Malicious Software Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for detecting and preventing the distribution of malicious software, such as malware, through application distribution servers are inadequate, as they fail to effectively identify and mitigate threats during the application distribution process without alerting attackers.

Innovation Solution

Implementing a honeypot workflow within the application distribution server to detect malicious behavior across multiple phases, including developer account creation, risk assessment, application upload, publication, promotion, and download, allowing the server to continue the process without alerting attackers, thereby gathering information on malicious activities and preventing malware distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional detection methods are used to identify malicious software, then security threats can be detected, but attackers are alerted and the distribution process is interrupted prematurely

Engineering Contradiction:
Improvedetection accuracyVSAvoidinformation on malicious behavior
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies the honeypot principle by allowing the malicious application to proceed through the distribution process under the guise of legitimacy. The system converts the harmful distribution process into a beneficial detection opportunity by monitoring the application's behavior at each phase (account creation, upload, publication, promotion, download) without alerting the attacker. This enables collection of valuable intelligence on malicious behavior patterns while maintaining the appearance of normal operation.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system performs preliminary monitoring and detection actions at each phase of the distribution process before the malicious application can cause harm. By establishing detection points at account creation, upload, publication, promotion, and download phases, the system proactively identifies malicious behavior early in the distribution chain while allowing the process to continue for intelligence gathering.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If the distribution process is interrupted upon detecting malicious behavior, then malware distribution is prevented, but the attacker is notified and cannot provide additional information

Engineering Contradiction:
Improvemalware distributionVSAvoidinformation on malicious activities
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system allows the malicious distribution process to continue under monitored conditions, converting what would normally be a harmful uninterrupted distribution into a beneficial controlled environment. The honeypot workflow enables the system to gather intelligence on the full extent of malicious activities including account creation patterns, upload behaviors, publication attempts, promotion strategies, and download patterns without alerting the attacker that their malware has been detected.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The distribution process is segmented into distinct phases (account creation, risk assessment, upload, publication, promotion, download), with detection mechanisms embedded at each segment. This segmentation allows the system to monitor specific malicious behaviors at appropriate phases while maintaining overall process continuity, preventing premature interruption that would alert the attacker.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If a trap system is used to continue phases without alerting attackers, then more information on malicious behavior can be gathered, but the system complexity increases

Engineering Contradiction:
Improveinformation on malicious behaviorVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The honeypot workflow is implemented as a segmented multi-phase process with specific detection and monitoring capabilities at each phase (account creation, risk assessment, upload, publication, promotion, download). This segmentation allows the complex monitoring functionality to be organized into manageable, phase-specific modules rather than a monolithic system, making the complexity more controllable and maintainable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The honeypot detection system serves multiple functions simultaneously: it monitors for malicious behavior, allows controlled continuation of the distribution process, gathers intelligence on attack patterns, and maintains the appearance of normal operation. This multi-functionality consolidates what would otherwise require separate systems into a single unified honeypot workflow platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2743858B1Using a honeypot workflow for software review
Publication Date: 2016.04.06 GOOGLE LLC
  • EP2743858B1 patent drawingFigure 1
  • EP2743858B1 patent drawingFigure 2
  • EP2743858B1 patent drawingFigure 3

AI summary

An application distribution server (102) may be operable to perform an application distribution process for an application, where the application distribution process may comprise a plurality of phases. The plurality of phases may comprise, in sequence, a developer account creation phase (302), a risk assessment phase (304), an application upload phase (306), an application publication phase (308), an application promotion phase (310) and an application download phase (312). The application distribution server (102) may detect, at each of the plurality of phases, whether a particular behavior corresponding to use of the application to distribute undesirable software may occur. In instances when an occurrence of the particular behavior is detected at a certain phase in the application distribution process, the application distribution server (102) may continue, utilizing a trap system, one or more subsequent phases after the certain phase for the application, without communicating information on the detection of the occurrence of the particular behavior.