Malware Detection via Virtual Machine Time Acceleration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malware authors use sophisticated techniques to obfuscate domain generation algorithms, making it difficult for security companies to detect and prevent malware communication with command and control servers, as traditional methods require reverse engineering and are prone to algorithm changes, leading to prolonged analysis times and ineffective remedial actions.
Innovation Solution
Implementing a data appliance with a DNS module and virtual machine servers that accelerate malware execution and collect algorithmically generated domains without requiring reverse engineering of the domain generation algorithm, using time-acceleration techniques and statistical analysis to identify and block malicious domain connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional reverse engineering methods are used to detect domain generation algorithms, then detection capability is improved, but analysis time increases significantly
Solution Approach 1:
The patent performs preliminary actions by executing the malware sample in a controlled environment before full analysis, collecting domain generation algorithm behavior data in advance. This allows the system to pre-identify suspicious patterns and domain generation mechanisms, so that when actual detection is needed, the analysis is already partially complete, significantly reducing the time required for full detection while maintaining high detection capability.
2Difficulty of detecting and measuring
If malware authors use sophisticated obfuscation techniques, then malware detection difficulty increases, but malware functionality remains effective
Solution Approach 1:
The patent introduces an intermediary controlled environment that mediates between the obfuscated malware and the detection system. This intermediary environment provides controlled inputs and captures outputs, allowing the detection system to observe the malware's actual behavior patterns without being fooled by obfuscation. The intermediary translates the obfuscated malware behavior into detectable signals, maintaining detection effectiveness while the malware's obfuscation remains intact.
3Measurement precision
If malware authors frequently change domain generation algorithms, then detection accuracy decreases, but malware adaptability increases
Solution Approach 1:
The patent implements a dynamic detection approach that adapts to changing malware behaviors. The system executes malware samples and observes their domain generation patterns in real-time, allowing it to detect and adapt to algorithm changes. By dynamically adjusting detection parameters based on observed behavior rather than relying on static signatures, the system maintains high detection accuracy even when malware authors frequently change their domain generation algorithms.
Data Source
AI summary
Detecting duplicate malware samples is disclosed. A first guest clock is set to a first value in a first virtual machine instance. A first malware sample is executed in the first virtual machine instance. A second guest clock value is set to the first value in a second virtual machine instance. A second malware sample is executed in the second virtual machine instance. A determination is made as to whether the first malware sample and the second malware sample are the same, based at least in part on performing a comparison of attempted external contacts generated by executing each of the respective first and second malware samples.


