Malware Analysis Data Sharing System for Detection Accuracy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems operating within an enterprise network often produce inconsistent malware detection outcomes due to different analysis focuses and rule sets, leading to false negatives and false positives, and lack effective sharing of contextual data to enhance detection and remediation efforts.

Innovation Solution

A malware analysis data sharing system that facilitates the sharing of contextual data between cybersecurity systems, including active and passive sharing methods, to improve malware detection by providing context information on object origination and behavior, thereby enhancing the analysis and classification processes and facilitating better remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple cybersecurity systems operate independently with different analysis focuses and rule sets, then each system can perform specialized malware detection, but inconsistent detection outcomes and false negatives/positives occur

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple independent cybersecurity systems into a unified architecture where detection results, contextual data, and analysis findings are shared across all systems. This merging approach ensures consistent malware detection outcomes while maintaining the specialized capabilities of each system through centralized data coordination.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a universal data sharing mechanism that enables all cybersecurity systems to access and utilize detection results and contextual information from any other system. This multi-functional approach allows each system to benefit from diverse analysis perspectives while maintaining its specialized detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If cybersecurity systems operate in separate silos with different rule sets, then each system can maintain independent detection logic, but false negatives and false positives increase

Engineering Contradiction:
Improvedetection verdict accuracyVSAvoidcontextual data sharing
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms where detection results and contextual data from one cybersecurity system are fed back to other systems. This feedback loop enables continuous refinement of detection accuracy by allowing systems to learn from and adjust based on findings from specialized analyses performed by other systems.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces intermediary components that facilitate information exchange between isolated cybersecurity systems. These intermediaries enable contextual data sharing without requiring direct integration between systems, thus reducing information loss while maintaining system independence.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If contextual data is shared between cybersecurity systems, then detection accuracy improves, but system complexity and data management overhead increase

Engineering Contradiction:
Improvemalware detection consistencyVSAvoiddata sharing infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs intermediary data sharing mechanisms that simplify the complexity of direct system-to-system communication. These intermediaries manage contextual data exchange, reducing the infrastructure complexity while enabling reliable detection consistency across all cybersecurity systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If comprehensive contextual data is collected and shared across all cybersecurity systems, then holistic view of malware attacks is achieved, but data processing overhead increases

Engineering Contradiction:
Improvecontextual information availabilityVSAvoiddata processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent extracts and shares only the essential contextual data elements that are most valuable for malware detection across systems. This selective extraction approach provides a holistic view of malware attacks while minimizing data processing overhead by excluding redundant or less critical information.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11856011B1Multi-vector malware detection data sharing system for improved detection
Publication Date: 2023.12.26 MAGENTA SECURITY HOLDINGS LLC
  • US11856011B1 patent drawing
  • US11856011B1 patent drawing
  • US11856011B1 patent drawing

AI summary

A computerized method for analyzing an object is disclosed. The computerized method includes obtaining, by a cybersecurity system, an object and context information generated during a first malware analysis of the object conducted prior to obtaining the object. Thereafter, the cybersecurity system performs a second malware analysis of the object to determine a verdict indicating maliciousness of the object. The scrutiny of the second malware analysis is adjusted based, at least in part, the context information, which may include (i) activating additional or different monitors, (ii) adjusting thresholds for determining maliciousness, or (iii) applying a modified rule set during the second malware analysis based on the context information.