Infection Verification Pack Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy security solutions fail to detect sophisticated malware techniques, leading to unauthorized access, data loss, downtime, and high recovery costs due to their inability to scale across diverse operating systems and software versions.

Innovation Solution

The Infection Verification Pack (IVP) system employs behavior detonation, machine-learning classification models, and transformation of persistent artifacts to detect malware across multiple endpoint systems with different operating systems and software versions, providing automated threat detection and response with low false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy security solutions use signature and heuristics matching, then they can detect known malware, but they fail to detect sophisticated malware techniques

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidability to detect sophisticated malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary behavior analysis of malware samples in isolated environments before deployment. By executing malware in controlled sandboxes and analyzing its behavior patterns, the system pre-computes behavioral signatures that can detect sophisticated malware variants without relying on traditional signature matching, thus improving both reliability and adaptability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces behavioral analysis as an intermediary layer between traditional signature-based detection and sophisticated malware. This intermediary analyzes malware behavior patterns, system calls, and execution characteristics to generate behavioral signatures that bridge the gap between known and unknown malware detection methods

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security solutions analyze agent behavior in isolated context, then they can identify malware characteristics, but they fail to scale across diverse operating systems and software versions

Engineering Contradiction:
Improvebehavior analysis accuracyVSAvoidscaling capability across platforms
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system creates universal behavioral signatures that function across multiple operating systems and software versions. By abstracting malware behavior patterns into platform-agnostic characteristics and using normalization techniques, the same detection mechanisms can be applied universally across diverse environments, maintaining both precision and scalability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms behavioral data into standardized parameters that can be compared across different operating systems. By normalizing system calls, execution patterns, and behavioral metrics into universal parameter sets, the system maintains measurement precision while enabling cross-platform scaling

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If traditional security solutions are deployed, then they provide basic malware detection, but they result in high cost to recover and repair infected computers

Engineering Contradiction:
Improvesecurity solution deploymentVSAvoidrecovery and repair costs
Core Design Contradiction:
Ease of manufactureVSLoss of energy

Solution Approach 1:

The system performs preliminary detection and analysis before malware can cause significant damage. By using behavioral analysis to identify infections early in their execution cycle, the system enables faster response and containment, reducing the overall cost and effort required for recovery and repair operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3111330B1System and method for verifying and detecting malware
Publication Date: 2020.01.29 CYPHORT INC
  • EP3111330B1 patent drawingFigure 1
  • EP3111330B1 patent drawingFigure 2
  • EP3111330B1 patent drawingFigure 3

AI summary

A system configured to detect malware is described. The system including an infection verification pack configured to perform behavior detonation; identify a malware object based on machine-learning; and select one or more persistent artifacts of the malware on the target system based on one or more algorithms applied to behavior traces of the malware object to select one or more persistent artifacts of the malware on the target system.