Malicious HTTP Chain Detection via Virtualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy security solutions fail to detect sophisticated malware infections that use HTTP chains to redirect users to malicious websites, exploit vulnerabilities, and obscure malware through encryption and obfuscation, leading to data loss, downtime, and high recovery costs.

Innovation Solution

A system and method that detect HTTP chains by analyzing a sequence of HTTP objects for events, generating a list of events, and using virtualization environments to simulate browser operations, allowing for the identification of malicious behavior and prevention of malware distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If legacy security solutions use signature and heuristics matching, then detection of known malware is improved, but detection of sophisticated malware using HTTP chains and obfuscation deteriorates

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidability to detect sophisticated malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the malware detection process into multiple components: HTTP chain analysis, virtualization environment simulation, event collection, and data model classification. This segmentation allows the system to handle sophisticated malware by breaking down the detection task into manageable parts that can analyze different aspects of potential threats

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization environment as an intermediary to simulate browser operations and analyze HTTP chains in isolation. This intermediary layer allows safe execution and observation of suspicious code without risking the actual system, enabling detection of sophisticated malware that would otherwise be undetectable by traditional methods

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If malware uses multiple redirects and obfuscation techniques, then evasion of detection is improved, but system complexity to counteract increases

Engineering Contradiction:
Improvemalware evasion capabilityVSAvoiddetection system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent performs preliminary analysis of HTTP chains before they execute in the actual system. By using virtualization to simulate browser operations in advance and collect events during this simulated execution, the system identifies malicious patterns before they can cause harm, reducing the need for complex real-time countermeasures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a virtualized copy of the browser environment to analyze HTTP chains. This copying approach allows the system to observe and analyze malicious behavior in a safe replica without affecting the real system, simplifying the detection architecture while maintaining high effectiveness against evasive malware

Inventive Principle:
Principle #26Copying

3Reliability

If traditional security analysis is performed in isolated context, then safety is improved, but detection of sophisticated techniques deteriorates

Engineering Contradiction:
Improveanalysis safetyVSAvoidsophisticated malware detection
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent creates a universal virtualization environment that can execute and analyze multiple types of HTTP chains and browser operations in a single isolated context. This multi-functional environment maintains safety while improving detection capability by allowing comprehensive analysis of sophisticated malware techniques that require contextual understanding

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3108401B1System and method for detection of malicious hypertext transfer protocol chains
Publication Date: 2019.10.16 CYPHORT INC
  • EP3108401B1 patent drawingFigure 1
  • EP3108401B1 patent drawingFigure 2
  • EP3108401B1 patent drawingFigure 3

AI summary

A system configured to detect malware is described. The system configured to detect malware including a data collector configured to detect at least a first hypertext transfer object in a chain of a plurality of hypertext transfer objects. The data collector further configured to analyze at least the first hypertext transfer object for one or more events. And, the data collector configured to generate a list of events based on the analysis of at least the first hypertext transfer object.