Malicious Software Detection via Multi-Environment Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting malicious software actions is complex due to the numerous and varied actions performed by software objects, making it difficult to identify illegitimate behavior without extensive rule-based systems that are prone to human errors and require continuous updates.

Innovation Solution

Executing a tested software object in multiple computing environments with different hardware and software configurations to identify differences in actions, which simplifies analysis and reduces reliance on predefined rules by highlighting undocumented or malicious behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If extensive rule-based systems are used to detect malicious software actions, then detection capability is improved, but system complexity and susceptibility to human errors increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of the software object and executes them in controlled virtual environments (sandboxes) rather than relying on complex rule-based systems. These virtual instances replicate the software's behavior in isolation, allowing observation of actions without requiring extensive predefined rules about what constitutes malicious behavior.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical rule-based detection system with an automated virtual execution and observation system. Instead of manually maintaining complex rule sets, the system automatically executes software objects in virtual environments and records their actions, substituting human-maintained rules with automated virtual experimentation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If rule-based detection systems are used, then detection capability is improved, but the need for continuous updates and maintenance increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidtime for updates and maintenance
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The virtual execution system performs self-service by automatically executing software objects in multiple virtual environments and recording their actions without requiring manual intervention. The system self-generates data about software behavior, eliminating the need for continuous manual updates to detection rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system maintains continuous operation by continuously executing software objects in virtual environments and recording their actions. This continuous monitoring and data collection process eliminates interruptions for rule updates, as the system learns from ongoing execution rather than requiring periodic manual reconfiguration.

Inventive Principle:
Principle #20Continuity of useful action

3Measurement precision

If multiple computing environments are used to test software actions, then detection accuracy is improved, but testing complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidtesting complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates multiple virtual copies of computing environments (sandboxes) that can be independently configured and executed. These virtual copies replicate different system states, software versions, and configurations without requiring physical complexity, allowing precise observation of software behavior across varied conditions.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system implements nested virtual environments where virtual machines or sandboxes are contained within a host system. This nesting structure allows multiple testing environments to be organized hierarchically, with inner virtual environments running within outer containment layers, simplifying the management of complex testing configurations.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11704410B2System and method for detecting suspicious actions of a software object
Publication Date: 2023.07.18 NEC CORPOATION OF AMERICA
  • US11704410B2 patent drawing
  • US11704410B2 patent drawing
  • US11704410B2 patent drawing

AI summary

A system for detecting malicious software, comprising at least one hardware processor adapted to: execute a tested software object in a plurality of computing environments each configured according to a different hardware and software configuration; monitor a plurality of computer actions performed in each of the plurality of computing environments when executing the tested software object; identify at least one difference between the plurality of computer actions performed in a first of the plurality of computing environments and the plurality of computer actions performed in a second of the plurality of computing environments; and instruct a presentation of an indication of the identified at least one difference on a hardware presentation unit.