Machine-Learning Cloud-Service Profiling for Real-Time Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud environments are increasingly vulnerable to malware infections, with existing detection methods being laborious, incomplete, and unable to detect new or unknown vulnerabilities, leading to security breaches and performance degradation.

Innovation Solution

A cloud-service malware detection application using machine learning to monitor inter-service activities and generate a service behavioral profile, automatically detecting anomalies and implementing threat procedures to protect cloud services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional malware detection methods are used, then detection coverage is limited, but detection speed and accuracy deteriorate

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and recording inter-service activities, API calls, and communications to establish baseline behavioral profiles before malware infection occurs. This pre-established knowledge enables rapid anomaly detection without time-consuming analysis during threat events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical signature-based detection methods with machine learning-based behavioral analysis. The system uses ML models to automatically analyze service behaviors, communications, and API calls, substituting manual rule-based approaches with intelligent automated detection that achieves both speed and accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If manual profiling of cloud services is performed, then detection accuracy improves, but system complexity and labor requirements increase

Engineering Contradiction:
Improveservice profiling accuracyVSAvoidprofiling system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically generating service behavioral profiles without manual intervention. The machine learning models autonomously analyze inter-service activities, communications, and API calls to create accurate service profiles, eliminating the need for manual profiling while maintaining high precision.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal profiling system that handles multiple cloud service types (containers, virtual machines, bare metal) through a single machine learning framework. This multi-functional approach achieves accurate profiling across diverse service architectures without increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive monitoring of inter-service activities is implemented, then malware detection capability improves, but computational resources and processing time increase

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts only the most relevant features from comprehensive inter-service activity data using machine learning. Instead of processing all raw data, the ML models identify and extract key behavioral indicators, communications patterns, and API call characteristics that are most indicative of malware, reducing computational overhead while maintaining detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by monitoring a selective subset of inter-service activities that are most indicative of malware behavior. The system focuses computational resources on critical communication channels and API calls rather than uniformly monitoring all activities, achieving effective malware detection with reduced resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

4Productivity

If adaptive profiling using machine learning is deployed, then scalability and accuracy improve, but initial setup time and computational training requirements increase

Engineering Contradiction:
Improvemalware detection scalabilityVSAvoidmodel training time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary machine learning model training during off-peak hours or initial deployment phases to establish service behavioral profiles before production use. This pre-training approach enables rapid real-time malware detection without computational delays during critical security events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic profiling where machine learning models continuously adapt and update service behavioral profiles as services evolve. The system dynamically adjusts to changing service behaviors while maintaining detection accuracy, allowing scalability without requiring complete retraining of models.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12445478B2Adaptive profiling of cloud services using machine learning for malware detection
Publication Date: 2025.10.14 CROWDSTRIKE
  • US12445478B2 patent drawing
  • US12445478B2 patent drawing
  • US12445478B2 patent drawing

AI summary

A cloud-service malware detection application detects, in real time or in near real time, malware infecting cloud services. The cloud-service malware detection application monitors incoming communications, outgoing communications, API calls, and other inter-service activities conducted between different cloud services in a cloud-computing environment. Because the cloud-computing environment may have many different cloud services, the cloud-service malware detection application detects a malware attack that spans multiple hosts and cloud services. The cloud-service malware detection application adaptively profiles each individual cloud service using machine learning, thus providing quicker, more accurate, and more scalable malware detection.