Malware Identifier Generation via Virtual Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Advanced Persistent Threat (APT) detection systems are resource-intensive and require offline training, making them inefficient for quick and accurate classification of malicious objects, especially those that morph within families.

Innovation Solution

A run-time classification system that uses a virtual execution environment to analyze anomalous behaviors of suspect objects against pre-stored family identifiers, enabling faster detection of APTs and non-APTs by comparing monitored behaviors to common indicators of compromise (IOCs) and generating family identifiers for known malware families.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If offline system and workforce training is used for APT classification, then classification accuracy is improved, but resource consumption and time required increase significantly

Engineering Contradiction:
Improveclassification accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary classification by comparing malware samples against pre-stored family identifiers and common indicators of compromise (IOCs) before full analysis is required. This allows rapid initial triage to distinguish APTs from non-APTs without requiring resource-intensive offline training for each classification task.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a database of pre-stored family identifiers and common IOCs that can be copied and reused for classification. Instead of training models offline for each new APT family, the system copies and compares against existing identifiers, significantly reducing computational resources needed for classification while maintaining accuracy.

Inventive Principle:
Principle #26Copying

2Measurement precision

If offline system and workforce training is used for APT classification, then classification accuracy is improved, but classification time increases

Engineering Contradiction:
Improveclassification accuracyVSAvoidclassification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary classification by comparing malware samples against pre-stored family identifiers and common indicators of compromise (IOCs) before full analysis is required. This allows rapid initial triage to distinguish APTs from non-APTs without requiring resource-intensive offline training for each classification task.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual offline training and analysis with automated computational comparison against pre-stored identifiers. The classification process substitutes human expert training with algorithmic matching against a database of known APT family characteristics, enabling rapid automated classification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If traditional malware classification methods are used, then detection capability is maintained, but adaptability to morphing malware decreases

Engineering Contradiction:
Improvedetection capabilityVSAvoidadaptability to morphing malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system monitors changes in malware behavior parameters and compares them against stored family identifiers. When malware morphs or evolves, the system can detect parameter changes and update classifications by comparing new behaviors against existing family profiles, maintaining detection capability while adapting to variations in malware techniques.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10467411B1System and method for generating a malware identifier
Publication Date: 2019.11.05 MAGENTA SECURITY HOLDINGS LLC
  • US10467411B1 patent drawing
  • US10467411B1 patent drawing
  • US10467411B1 patent drawing

AI summary

One embodiment of the disclosure is directed to a method for generating an identifier for use in malware detection. Herein, a first plurality of indicators of compromise are obtained. These indicators of compromise correspond to a plurality of anomalous behaviors. Thereafter, a filtering operation is performed on the first plurality of indicators of compromise by removing one or more indicators of compromise from the first plurality of indicators of compromise to create a second plurality of indicators of compromise. The identifier represented by the second plurality of indicators of compromise is created.