Malware Identifier Generation via Virtual Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Advanced Persistent Threat (APT) detection systems are resource-intensive and require offline training, making them inefficient for quick and accurate classification of malicious objects, especially those that morph within families.
Innovation Solution
A run-time classification system that uses a virtual execution environment to analyze anomalous behaviors of suspect objects against pre-stored family identifiers, enabling faster detection of APTs and non-APTs by comparing monitored behaviors to common indicators of compromise (IOCs) and generating family identifiers for known malware families.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If offline system and workforce training is used for APT classification, then classification accuracy is improved, but resource consumption and time required increase significantly
Solution Approach 1:
The system performs preliminary classification by comparing malware samples against pre-stored family identifiers and common indicators of compromise (IOCs) before full analysis is required. This allows rapid initial triage to distinguish APTs from non-APTs without requiring resource-intensive offline training for each classification task.
Solution Approach 2:
The patent creates a database of pre-stored family identifiers and common IOCs that can be copied and reused for classification. Instead of training models offline for each new APT family, the system copies and compares against existing identifiers, significantly reducing computational resources needed for classification while maintaining accuracy.
2Measurement precision
If offline system and workforce training is used for APT classification, then classification accuracy is improved, but classification time increases
Solution Approach 1:
The system performs preliminary classification by comparing malware samples against pre-stored family identifiers and common indicators of compromise (IOCs) before full analysis is required. This allows rapid initial triage to distinguish APTs from non-APTs without requiring resource-intensive offline training for each classification task.
Solution Approach 2:
The patent replaces manual offline training and analysis with automated computational comparison against pre-stored identifiers. The classification process substitutes human expert training with algorithmic matching against a database of known APT family characteristics, enabling rapid automated classification.
3Reliability
If traditional malware classification methods are used, then detection capability is maintained, but adaptability to morphing malware decreases
Solution Approach 1:
The system monitors changes in malware behavior parameters and compares them against stored family identifiers. When malware morphs or evolves, the system can detect parameter changes and update classifications by comparing new behaviors against existing family profiles, maintaining detection capability while adapting to variations in malware techniques.
Data Source
AI summary
One embodiment of the disclosure is directed to a method for generating an identifier for use in malware detection. Herein, a first plurality of indicators of compromise are obtained. These indicators of compromise correspond to a plurality of anomalous behaviors. Thereafter, a filtering operation is performed on the first plurality of indicators of compromise by removing one or more indicators of compromise from the first plurality of indicators of compromise to create a second plurality of indicators of compromise. The identifier represented by the second plurality of indicators of compromise is created.


