Multi-Core Malicious Code Analysis via Monitoring Core Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malicious code analysis technologies face difficulties in detecting and analyzing behavior of code that evades virtual environments, as they can only extract post-execution results from hard disks, making real-time monitoring and analysis challenging, especially when network communication involves encrypted data.

Innovation Solution

A multi-core CPU-based apparatus that sets monitoring cores to collect behavioral information from shared resources like disk, memory, and cache, using a program flow tracer and hardware debugging device, allowing for real-time monitoring and analysis of malicious code behavior without additional devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malicious code is executed in a virtual environment for analysis, then the analysis process can be separated from the user environment and system restoration is rapid, but malicious code can recognize the virtual environment and perform different operations to evade detection

Engineering Contradiction:
Improveanalysis separation from user environmentVSAvoiddetection of malicious code behavior
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system divides the CPU into multiple cores, with at least one core dedicated to executing monitoring programs while other cores execute the analysis target code. This segmentation allows the monitoring function to be separated from the execution function, enabling independent observation of malicious code behavior without interference from the virtual environment itself.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a monitoring core as an intermediary component that observes the execution of malicious code on other cores. This intermediary structure allows the system to detect malicious behavior indirectly through the monitoring programs, bypassing the need for direct interaction with the virtual environment that malicious code can exploit.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If hard disk forensic method is used to extract behavior information after execution, then the system can extract results of malicious code, but detailed behavior occurring during execution cannot be extracted

Engineering Contradiction:
Improveextraction of malicious code resultsVSAvoiddetailed behavior information
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

Instead of extracting information after execution completes, the system performs preliminary monitoring during the execution process. The monitoring programs run concurrently with the analysis target code, capturing behavioral information in real-time as it executes, thereby preserving detailed intermediate behavior data that would otherwise be lost.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring programs continuously collect behavioral information throughout the execution process rather than relying on discrete post-execution extraction. This continuous monitoring ensures that all detailed behaviors, including intermediate steps and real-time operations, are captured and stored for comprehensive analysis.

Inventive Principle:
Principle #20Continuity of useful action

3Loss of information

If network packets are extracted and stored to observe network behavior, then network behavior and accessed addresses can be analyzed, but encrypted data prevents analysis of malicious code

Engineering Contradiction:
Improvenetwork behavior informationVSAvoidanalysis of encrypted malicious code
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The system extracts and analyzes behavioral information directly from the execution environment through monitoring programs, rather than relying on network packet extraction. This approach allows the system to observe malicious code behavior at the source, including encrypted communications, without needing to decrypt the data, thereby maintaining measurement precision for encrypted content.

Inventive Principle:
Principle #2Taking out (Extraction)

4Measurement precision

If multi-core CPU is used with monitoring cores, then real-time monitoring of malicious code can be performed outside execution environment, but device complexity increases

Engineering Contradiction:
Improvereal-time behavior monitoringVSAvoidCPU core configuration
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent leverages the existing multi-core CPU architecture to serve dual purposes: execution of analysis target code and execution of monitoring programs. By utilizing the same hardware resources (CPU cores, memory, cache) for both functions, the system avoids adding separate dedicated monitoring hardware, thereby reducing the increase in device complexity while maintaining real-time monitoring capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9965631B2Apparatus and method for analyzing malicious code in multi-core environment using a program flow tracer
Publication Date: 2018.05.08 ELECTRONICS & TELECOMM RES INST
  • US9965631B2 patent drawing
  • US9965631B2 patent drawing
  • US9965631B2 patent drawing

AI summary

Disclosed herein are an apparatus and method for analyzing malicious code in a multi-core environment. The apparatus for analyzing malicious code includes a core setting unit for setting at least one monitoring core, on which malicious code is to be monitored, among cores of a multi-core Central Processing Unit (CPU), and executing a monitoring program on the monitoring core, a behavioral information collection unit for, when execution cores that are not set as the monitoring core execute analysis target code, collecting pieces of behavioral information using the monitoring program and a hardware debugging device, and a storage unit for storing the behavioral information.