Malware Detection via Human-Like Browser Interaction Profiles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anti-virus and anti-malware systems are ineffective in detecting malware without prior knowledge of its signature, as sophisticated malware can detect and evade detection in emulated or sandbox environments, leading to potential infections.
Innovation Solution
A malware detection system that utilizes a control system to mimic human user interactions by creating personality profiles to access public networks, allowing the system to detect and analyze malware without being recognized as a controlled environment, and store information for prevention strategies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional anti-virus systems use signature-based detection methods, then detection accuracy for known malware is improved, but the system becomes ineffective against new or unknown malware variants
Solution Approach 1:
The system changes the parameters of browser interaction by introducing human-like variability in timing, navigation patterns, and input sequences. Instead of deterministic automated browsing, the system varies parameters such as pause durations, click positions, and navigation choices to create unpredictable interaction patterns that prevent malware detection while maintaining effective scanning capability
Solution Approach 2:
The system transitions from static, predetermined browsing sequences to dynamic, adaptive navigation that responds to page content and employs randomization. The browsing behavior becomes flexible and changeable, adjusting interaction patterns based on the specific webpage being analyzed, which prevents malware from detecting a fixed automated script
2Object-affected harmful factors
If malware is executed in sandboxed or emulated environments for safe analysis, then user safety is improved, but sophisticated malware can detect the virtual environment and cease functioning
Solution Approach 1:
The system introduces a layer of intermediary human-like interaction between the automated control system and the malware. By using a simulated human user profile that mediates all interactions with the webpage, the system creates an indistinguishable interface that prevents malware from detecting the automated nature of the environment while still allowing safe execution and analysis
Solution Approach 2:
The system modifies environmental parameters by introducing variability in interaction timing, navigation patterns, and input sequences. This changes the static sandbox environment into a dynamic one that mimics human behavior, preventing malware from reliably detecting the virtual environment through traditional means
3Productivity
If automated scripts are used to browse webpages for malware detection, then scanning efficiency is improved, but malware can detect automation and evade detection
Solution Approach 1:
The system transforms rigid automated scripts into dynamic browsing behavior that incorporates randomization and adaptive responses. Navigation sequences, interaction timing, and input patterns become variable rather than fixed, allowing the system to maintain high scanning efficiency while presenting an unpredictable interface that prevents malware from detecting automation
Solution Approach 2:
The system performs preliminary setup of a human user profile with predetermined interaction patterns, preferences, and behavior characteristics before executing the browsing task. This preliminary configuration establishes a consistent human-like persona that can be reused across multiple scanning operations, maintaining efficiency while preventing detection
Data Source
AI summary
Aspects of the present disclosure involve systems and methods computing devices to access a public network posing as a user to the network to detect one or more malware programs available for downloading through the network. More particularly, a malware detection control system utilizes a browser executed on a computing device to access a public network, such as the Internet. Through the browser, sites or nodes of the public network are accessed by the control system with the interactions with the sites of the public network designed to mimic or approximate a human user of the browser. More particularly, the control system may apply the one or more personality profiles to the browser of the computing device to access and interact with the nodes of the public network. Further, the control system may monitor the information retrieved from the network sites to detect the presence of malware within the nodes.


