Malware Characterization via Multi-Sensor Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection methods are manual, labor-intensive, and lack automated tools for characterizing malware characteristics, making it difficult to detect and remediate malware infections, especially in complex software systems with intricate data dependencies, and are not effective in dynamically adapting to changing malware behaviors.
Innovation Solution
A method and system for malware characterization and prediction that utilizes a combination of sensor payloads to correlate anomalies in processing functions, leveraging machine learning and side-channel observations to identify potential malware infections and automate remediation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual malware characterization is performed, then detection accuracy can be maintained through expert analysis, but the process becomes extremely time-consuming and labor-intensive
Solution Approach 1:
The system enables automated malware characterization by having the malware itself execute within a controlled virtual environment, where its actions are automatically tracked and analyzed through sensor payloads. The system serves itself by generating characterization data through the malware's own behavior rather than requiring external manual analysis.
Solution Approach 2:
Manual expert analysis is replaced with an automated computational system that uses sensor payloads to collect data and machine learning algorithms to analyze malware behavior. The mechanical process of human analysts examining malware is substituted with electronic data collection and automated pattern recognition.
2Area of stationary object
If traditional network scanning tools are used to locate infected devices, then detection coverage can be achieved, but the tools cause industrial control systems to crash
Solution Approach 1:
A virtual machine environment acts as an intermediary between the malware and the host system. The malware executes in the virtual machine, which isolates it from the physical ICS devices. This intermediary layer allows detection without direct interaction that would cause system crashes.
Solution Approach 2:
The system segments the execution environment by creating virtual machine instances that are isolated from the physical ICS infrastructure. Each sensor payload operates in its own segmented space, allowing comprehensive monitoring without affecting the stability of the underlying physical systems.
3Measurement precision
If static signature-based detection is used, then known malware can be identified, but the system cannot dynamically adapt to new malware characteristics or zero-day attacks
Solution Approach 1:
The system transitions from static signature matching to dynamic behavior analysis. Sensor payloads continuously monitor malware execution in real-time, capturing changing characteristics as the malware interacts with the virtual environment. This dynamic approach allows the system to detect both known and unknown malware based on their behavioral patterns rather than fixed signatures.
Solution Approach 2:
The system performs preliminary characterization by executing malware in a controlled virtual environment before deployment. This preliminary action captures baseline behavior patterns that can be used for future detection, allowing the system to prepare detection signatures from actual malware behavior rather than relying on external threat intelligence.
4Measurement precision
If comprehensive sensor payloads are deployed to capture all malware characteristics, then detection capability is improved, but system complexity and resource requirements increase
Solution Approach 1:
The sensor payload architecture uses multi-functional components that can capture multiple types of data through unified interfaces. The virtual machine monitor serves multiple purposes: executing malware, collecting sensor data, and isolating threats. This universality reduces overall system complexity despite the comprehensive nature of the monitoring.
Data Source
AI summary
A method, apparatus and system for malware characterization includes receiving data identifying a presence of at least one anomaly of a respective portion of a processing function captured by at least one of each of at least two different sensor payloads and one sensor payload at two different times, determining a correlation between the at least two anomalies identified by the data captured by the at least one sensor payloads, and determining a presence of malware in the processing function based on the determined correlation. The method, apparatus and system can further include predicting an occurrence of at least one anomaly in the network based on at least one of current sensor payload data or previously observed and stored sensor payload data, recommending and/or initiating a remediation action and reporting a result of the malware characterization to a user.


