Malware Visualization Graph for Exploit Relationship Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat detection systems fail to effectively identify relationships between malicious exploits, making it difficult for security personnel to understand potential effects and lack the ability to generate reference models for comparison against future events.

Innovation Solution

A malware detection and visualization system that uses a machine learning engine to generate reference models from observed data, allowing for comparison with incoming data and providing interactive display screens to illustrate relationships between malicious events, enabling better exploit detection and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If a list format is used to present exploit information, then security personnel receive information about uncovered exploits, but the system fails to identify relationships between exploits

Engineering Contradiction:
Improverelationship information between exploitsVSAvoidsystem complexity for relationship analysis
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent transforms the traditional list-format presentation of exploit information into a multi-dimensional visual graph structure. Nodes represent exploits, processes, or files while edges represent relationships between them. This dimensional transformation enables security personnel to perceive relationships between exploits that are invisible in linear list formats, directly resolving the information loss problem without requiring complex analytical systems.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system creates visual copies of exploit data in graph format, where each exploit is represented as a node and relationships as edges. This visual copying allows security personnel to simultaneously view multiple exploits and their interconnections, making relationship identification intuitive without adding system complexity.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If reference models are generated from observed exploits, then comparison against future events is enabled, but the system requires advanced machine learning capabilities

Engineering Contradiction:
Improveability to compare against future eventsVSAvoidmachine learning engine complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by generating reference models from observed exploit patterns before future exploits occur. The graph visualization system captures relationships between exploits, processes, and files during observed infections, stores these as reference models, and enables later comparison against new events. This preliminary modeling approach enables adaptability without requiring complex real-time machine learning during threat detection.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If interactive display screens are implemented, then visualization of malicious events is improved, but the system requires additional processing resources

Engineering Contradiction:
Improveease of understanding malicious eventsVSAvoidprocessing resources for visualization
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The system creates visual copies of exploit relationship data in an interactive graph display, where nodes and edges represent exploits and their relationships. This visual copying presents complex relationship information in an intuitive format that is easy to understand, while the actual heavy processing occurs during reference model generation rather than during visualization rendering.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs the computationally intensive work of analyzing exploit relationships and generating reference models in advance. Once these reference models are created, the interactive display screens can efficiently render visualizations by comparing new events against pre-generated models, reducing real-time processing resource requirements.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10868818B1Systems and methods for generation of signature generation using interactive infection visualizations
Publication Date: 2020.12.15 MAGENTA SECURITY HOLDINGS LLC
  • US10868818B1 patent drawing
  • US10868818B1 patent drawing
  • US10868818B1 patent drawing

AI summary

According to one embodiment, a malware detection and visualization system includes one or more processors; and a storage module communicatively coupled to the one or more processors, the storage module comprises logic, upon execution by the one or more processors, that accesses a first set of information that comprises (i) information directed to a plurality of observed events and (ii) information directed to one or more relationships that identify an association between different observed events of the plurality of observed events; and generates a reference model based on the first set of information, the reference model comprises at least a first event of the plurality of observed events, a second event of the plurality of observed events, and a first relationship that identifies that the second event is based on the first event, wherein at least one of (i) the plurality of observed events or (ii) the one or more relationships constitutes an anomalous behavior is provided.