Malware Detection via Virtual Machine Time Acceleration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware authors use sophisticated techniques to obfuscate domain generation algorithms, making it difficult for security companies to detect and prevent malware communication with command and control servers, as traditional methods require reverse engineering and are prone to algorithm changes, leading to prolonged analysis times and ineffective remedial actions.

Innovation Solution

Implementing a data appliance with a DNS module and virtual machine servers that accelerate malware execution and collect algorithmically generated domains without requiring reverse engineering of the domain generation algorithm, using time-acceleration techniques and statistical analysis to identify and block malicious domain connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional reverse engineering methods are used to detect domain generation algorithms, then detection capability is improved, but analysis time increases significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by executing the malware sample in a controlled environment before full analysis, collecting domain generation algorithm behavior data in advance. This allows the system to pre-identify suspicious patterns and domain generation mechanisms, so that when actual detection is needed, the analysis is already partially complete, significantly reducing the time required for full detection while maintaining high detection capability.

Inventive Principle:
Principle #10Preliminary action

2Difficulty of detecting and measuring

If malware authors use sophisticated obfuscation techniques, then malware detection difficulty increases, but malware functionality remains effective

Engineering Contradiction:
Improvedetection difficultyVSAvoidmalware effectiveness
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent introduces an intermediary controlled environment that mediates between the obfuscated malware and the detection system. This intermediary environment provides controlled inputs and captures outputs, allowing the detection system to observe the malware's actual behavior patterns without being fooled by obfuscation. The intermediary translates the obfuscated malware behavior into detectable signals, maintaining detection effectiveness while the malware's obfuscation remains intact.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If malware authors frequently change domain generation algorithms, then detection accuracy decreases, but malware adaptability increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidmalware adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic detection approach that adapts to changing malware behaviors. The system executes malware samples and observes their domain generation patterns in real-time, allowing it to detect and adapt to algorithm changes. By dynamically adjusting detection parameters based on observed behavior rather than relying on static signatures, the system maintains high detection accuracy even when malware authors frequently change their domain generation algorithms.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10152597B1Deduplicating malware
Publication Date: 2018.12.11 PALO ALTO NETWORKS INC
  • US10152597B1 patent drawing
  • US10152597B1 patent drawing
  • US10152597B1 patent drawing

AI summary

Detecting duplicate malware samples is disclosed. A first guest clock is set to a first value in a first virtual machine instance. A first malware sample is executed in the first virtual machine instance. A second guest clock value is set to the first value in a second virtual machine instance. A second malware sample is executed in the second virtual machine instance. A determination is made as to whether the first malware sample and the second malware sample are the same, based at least in part on performing a comparison of attempted external contacts generated by executing each of the respective first and second malware samples.