Malware Detection via Human-Like Browser Interaction Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-virus and anti-malware systems are ineffective in detecting malware without prior knowledge of its signature, as sophisticated malware can detect and evade detection in emulated or sandbox environments, leading to potential infections.

Innovation Solution

A malware detection system that utilizes a control system to mimic human user interactions by creating personality profiles to access public networks, allowing the system to detect and analyze malware without being recognized as a controlled environment, and store information for prevention strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional anti-virus systems use signature-based detection methods, then detection accuracy for known malware is improved, but the system becomes ineffective against new or unknown malware variants

Engineering Contradiction:
Improvedetection accuracyVSAvoideffectiveness against unknown malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system changes the parameters of browser interaction by introducing human-like variability in timing, navigation patterns, and input sequences. Instead of deterministic automated browsing, the system varies parameters such as pause durations, click positions, and navigation choices to create unpredictable interaction patterns that prevent malware detection while maintaining effective scanning capability

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system transitions from static, predetermined browsing sequences to dynamic, adaptive navigation that responds to page content and employs randomization. The browsing behavior becomes flexible and changeable, adjusting interaction patterns based on the specific webpage being analyzed, which prevents malware from detecting a fixed automated script

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If malware is executed in sandboxed or emulated environments for safe analysis, then user safety is improved, but sophisticated malware can detect the virtual environment and cease functioning

Engineering Contradiction:
Improveuser safetyVSAvoiddetection reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system introduces a layer of intermediary human-like interaction between the automated control system and the malware. By using a simulated human user profile that mediates all interactions with the webpage, the system creates an indistinguishable interface that prevents malware from detecting the automated nature of the environment while still allowing safe execution and analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system modifies environmental parameters by introducing variability in interaction timing, navigation patterns, and input sequences. This changes the static sandbox environment into a dynamic one that mimics human behavior, preventing malware from reliably detecting the virtual environment through traditional means

Inventive Principle:
Principle #35Parameter changes

3Productivity

If automated scripts are used to browse webpages for malware detection, then scanning efficiency is improved, but malware can detect automation and evade detection

Engineering Contradiction:
Improvescanning efficiencyVSAvoidmalware evasion capability
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The system transforms rigid automated scripts into dynamic browsing behavior that incorporates randomization and adaptive responses. Navigation sequences, interaction timing, and input patterns become variable rather than fixed, allowing the system to maintain high scanning efficiency while presenting an unpredictable interface that prevents malware from detecting automation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary setup of a human user profile with predetermined interaction patterns, preferences, and behavior characteristics before executing the browsing task. This preliminary configuration establishes a consistent human-like persona that can be reused across multiple scanning operations, maintaining efficiency while preventing detection

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11552988B2Creating malware prevention rules using malware detection and prevention system
Publication Date: 2023.01.10 LEVEL 3 COMMUNICATIONS LLC
  • US11552988B2 patent drawing
  • US11552988B2 patent drawing
  • US11552988B2 patent drawing

AI summary

Aspects of the present disclosure involve systems and methods computing devices to access a public network posing as a user to the network to detect one or more malware programs available for downloading through the network. More particularly, a malware detection control system utilizes a browser executed on a computing device to access a public network, such as the Internet. Through the browser, sites or nodes of the public network are accessed by the control system with the interactions with the sites of the public network designed to mimic or approximate a human user of the browser. More particularly, the control system may apply the one or more personality profiles to the browser of the computing device to access and interact with the nodes of the public network. Further, the control system may monitor the information retrieved from the network sites to detect the presence of malware within the nodes.