Malware Visualization Graph for Exploit Relationship Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current threat detection systems fail to effectively identify relationships between malicious exploits, making it difficult for security personnel to understand potential effects and lack the ability to generate reference models for comparison against future events.
Innovation Solution
A malware detection and visualization system that uses a machine learning engine to generate reference models from observed data, allowing for comparison with incoming data and providing interactive display screens to illustrate relationships between malicious events, enabling better exploit detection and visualization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If a list format is used to present exploit information, then security personnel receive information about uncovered exploits, but the system fails to identify relationships between exploits
Solution Approach 1:
The patent transforms the traditional list-format presentation of exploit information into a multi-dimensional visual graph structure. Nodes represent exploits, processes, or files while edges represent relationships between them. This dimensional transformation enables security personnel to perceive relationships between exploits that are invisible in linear list formats, directly resolving the information loss problem without requiring complex analytical systems.
Solution Approach 2:
The system creates visual copies of exploit data in graph format, where each exploit is represented as a node and relationships as edges. This visual copying allows security personnel to simultaneously view multiple exploits and their interconnections, making relationship identification intuitive without adding system complexity.
2Adaptability or versatility
If reference models are generated from observed exploits, then comparison against future events is enabled, but the system requires advanced machine learning capabilities
Solution Approach 1:
The system performs preliminary actions by generating reference models from observed exploit patterns before future exploits occur. The graph visualization system captures relationships between exploits, processes, and files during observed infections, stores these as reference models, and enables later comparison against new events. This preliminary modeling approach enables adaptability without requiring complex real-time machine learning during threat detection.
3Ease of operation
If interactive display screens are implemented, then visualization of malicious events is improved, but the system requires additional processing resources
Solution Approach 1:
The system creates visual copies of exploit relationship data in an interactive graph display, where nodes and edges represent exploits and their relationships. This visual copying presents complex relationship information in an intuitive format that is easy to understand, while the actual heavy processing occurs during reference model generation rather than during visualization rendering.
Solution Approach 2:
The system performs the computationally intensive work of analyzing exploit relationships and generating reference models in advance. Once these reference models are created, the interactive display screens can efficiently render visualizations by comparing new events against pre-generated models, reducing real-time processing resource requirements.
Data Source
AI summary
According to one embodiment, a malware detection and visualization system includes one or more processors; and a storage module communicatively coupled to the one or more processors, the storage module comprises logic, upon execution by the one or more processors, that accesses a first set of information that comprises (i) information directed to a plurality of observed events and (ii) information directed to one or more relationships that identify an association between different observed events of the plurality of observed events; and generates a reference model based on the first set of information, the reference model comprises at least a first event of the plurality of observed events, a second event of the plurality of observed events, and a first relationship that identifies that the second event is based on the first event, wherein at least one of (i) the plurality of observed events or (ii) the one or more relationships constitutes an anomalous behavior is provided.


