Malware Characterization via Multi-Sensor Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection methods are manual, labor-intensive, and lack automated tools for characterizing malware characteristics, making it difficult to detect and remediate malware infections, especially in complex software systems with intricate data dependencies, and are not effective in dynamically adapting to changing malware behaviors.

Innovation Solution

A method and system for malware characterization and prediction that utilizes a combination of sensor payloads to correlate anomalies in processing functions, leveraging machine learning and side-channel observations to identify potential malware infections and automate remediation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual malware characterization is performed, then detection accuracy can be maintained through expert analysis, but the process becomes extremely time-consuming and labor-intensive

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidtime for malware characterization
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automated malware characterization by having the malware itself execute within a controlled virtual environment, where its actions are automatically tracked and analyzed through sensor payloads. The system serves itself by generating characterization data through the malware's own behavior rather than requiring external manual analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual expert analysis is replaced with an automated computational system that uses sensor payloads to collect data and machine learning algorithms to analyze malware behavior. The mechanical process of human analysts examining malware is substituted with electronic data collection and automated pattern recognition.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Area of stationary object

If traditional network scanning tools are used to locate infected devices, then detection coverage can be achieved, but the tools cause industrial control systems to crash

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem stability
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

A virtual machine environment acts as an intermediary between the malware and the host system. The malware executes in the virtual machine, which isolates it from the physical ICS devices. This intermediary layer allows detection without direct interaction that would cause system crashes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the execution environment by creating virtual machine instances that are isolated from the physical ICS infrastructure. Each sensor payload operates in its own segmented space, allowing comprehensive monitoring without affecting the stability of the underlying physical systems.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If static signature-based detection is used, then known malware can be identified, but the system cannot dynamically adapt to new malware characteristics or zero-day attacks

Engineering Contradiction:
Improvemalware identification accuracyVSAvoiddynamic adaptation to malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system transitions from static signature matching to dynamic behavior analysis. Sensor payloads continuously monitor malware execution in real-time, capturing changing characteristics as the malware interacts with the virtual environment. This dynamic approach allows the system to detect both known and unknown malware based on their behavioral patterns rather than fixed signatures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary characterization by executing malware in a controlled virtual environment before deployment. This preliminary action captures baseline behavior patterns that can be used for future detection, allowing the system to prepare detection signatures from actual malware behavior rather than relying on external threat intelligence.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If comprehensive sensor payloads are deployed to capture all malware characteristics, then detection capability is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvemalware characteristic detectionVSAvoidsensor payload architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The sensor payload architecture uses multi-functional components that can capture multiple types of data through unified interfaces. The virtual machine monitor serves multiple purposes: executing malware, collecting sensor data, and isolating threats. This universality reduces overall system complexity despite the comprehensive nature of the monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11575688B2Method of malware characterization and prediction
Publication Date: 2023.02.07 SRI INTERNATIONAL
  • US11575688B2 patent drawing
  • US11575688B2 patent drawing
  • US11575688B2 patent drawing

AI summary

A method, apparatus and system for malware characterization includes receiving data identifying a presence of at least one anomaly of a respective portion of a processing function captured by at least one of each of at least two different sensor payloads and one sensor payload at two different times, determining a correlation between the at least two anomalies identified by the data captured by the at least one sensor payloads, and determining a presence of malware in the processing function based on the determined correlation. The method, apparatus and system can further include predicting an occurrence of at least one anomaly in the network based on at least one of current sensor payload data or previously observed and stored sensor payload data, recommending and/or initiating a remediation action and reporting a result of the malware characterization to a user.