Malicious Software Detection via Multi-Environment Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Detecting malicious software actions is complex due to the numerous and varied actions performed by software objects, making it difficult to identify illegitimate behavior without extensive rule-based systems that are prone to human errors and require continuous updates.
Innovation Solution
Executing a tested software object in multiple computing environments with different hardware and software configurations to identify differences in actions, which simplifies analysis and reduces reliance on predefined rules by highlighting undocumented or malicious behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If extensive rule-based systems are used to detect malicious software actions, then detection capability is improved, but system complexity and susceptibility to human errors increase
Solution Approach 1:
The patent creates virtual copies of the software object and executes them in controlled virtual environments (sandboxes) rather than relying on complex rule-based systems. These virtual instances replicate the software's behavior in isolation, allowing observation of actions without requiring extensive predefined rules about what constitutes malicious behavior.
Solution Approach 2:
The patent replaces the mechanical rule-based detection system with an automated virtual execution and observation system. Instead of manually maintaining complex rule sets, the system automatically executes software objects in virtual environments and records their actions, substituting human-maintained rules with automated virtual experimentation.
2Reliability
If rule-based detection systems are used, then detection capability is improved, but the need for continuous updates and maintenance increases
Solution Approach 1:
The virtual execution system performs self-service by automatically executing software objects in multiple virtual environments and recording their actions without requiring manual intervention. The system self-generates data about software behavior, eliminating the need for continuous manual updates to detection rules.
Solution Approach 2:
The system maintains continuous operation by continuously executing software objects in virtual environments and recording their actions. This continuous monitoring and data collection process eliminates interruptions for rule updates, as the system learns from ongoing execution rather than requiring periodic manual reconfiguration.
3Measurement precision
If multiple computing environments are used to test software actions, then detection accuracy is improved, but testing complexity increases
Solution Approach 1:
The patent creates multiple virtual copies of computing environments (sandboxes) that can be independently configured and executed. These virtual copies replicate different system states, software versions, and configurations without requiring physical complexity, allowing precise observation of software behavior across varied conditions.
Solution Approach 2:
The system implements nested virtual environments where virtual machines or sandboxes are contained within a host system. This nesting structure allows multiple testing environments to be organized hierarchically, with inner virtual environments running within outer containment layers, simplifying the management of complex testing configurations.
Data Source
AI summary
A system for detecting malicious software, comprising at least one hardware processor adapted to: execute a tested software object in a plurality of computing environments each configured according to a different hardware and software configuration; monitor a plurality of computer actions performed in each of the plurality of computing environments when executing the tested software object; identify at least one difference between the plurality of computer actions performed in a first of the plurality of computing environments and the plurality of computer actions performed in a second of the plurality of computing environments; and instruct a presentation of an indication of the identified at least one difference on a hardware presentation unit.


