Malware Detection Using Reference Model Relationship Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber security systems fail to effectively identify relationships between malicious exploits and generate reference models for comparison with future events, leading to incomplete threat detection and prevention.

Innovation Solution

A malware detection and visualization system that uses machine learning to generate reference models from observed data, allowing for real-time and forensic analysis of network traffic and endpoint device data to detect and visualize potential malware threats by comparing incoming data with known malicious behaviors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If current threat detection systems present exploit information in a list format, then security personnel receive information about uncovered exploits, but the systems fail to identify relationships between exploits that would help understand potential effects

Engineering Contradiction:
Improverelationship information between exploitsVSAvoidsystem complexity for generating reference models
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system performs preliminary analysis by generating reference models from observed exploits and malicious behaviors before comparison with new events. This advance preparation enables the system to identify relationships between exploits and predict potential effects, rather than merely listing detected exploits after the fact.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates simplified representations (reference models) that copy the essential characteristics and relationships of complex exploit behaviors. These reference models capture the structural patterns of malicious activities, enabling efficient comparison and relationship identification without requiring analysis of the full complexity of each individual exploit.

Inventive Principle:
Principle #26Copying

2Measurement precision

If the system generates reference models from observed exploits and malicious behaviors, then exploit detection accuracy improves, but the processing time and computational resources increase

Engineering Contradiction:
Improveexploit detection accuracyVSAvoidtime for generating and comparing reference models
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts only the essential and relevant features from observed exploits and malicious behaviors to create reference models. By taking out only the critical characteristics needed for detection rather than analyzing complete exploit data, the system achieves high detection accuracy while reducing computational overhead and processing time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transforms raw exploit data into standardized reference model parameters that facilitate efficient comparison. By changing the representation parameters of exploit data into structured models with defined attributes and relationships, the system enables faster matching and detection while maintaining high precision.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If the system provides detailed visual representation of exploit relationships, then security personnel can better understand malicious activities, but the information presentation complexity increases

Engineering Contradiction:
Improveunderstanding of malicious activity relationshipsVSAvoidease of interpreting visual information
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system segments the complex web of exploit relationships into discrete, manageable visual elements representing different aspects of malicious activities. By dividing the overall exploit structure into separate visual components (such as individual malicious events, their relationships, and potential effects), the system enables security personnel to understand relationships without being overwhelmed by complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9773112B1Exploit detection of malware and malware families
Publication Date: 2017.09.26 MAGENTA SECURITY HOLDINGS LLC
  • US9773112B1 patent drawing
  • US9773112B1 patent drawing
  • US9773112B1 patent drawing

AI summary

According to one embodiment, a computerized method comprises, accessing information associated with one or more observed events, wherein one or more of the observed events constitutes an anomalous behavior; accessing a reference model based on a first plurality of events, the reference model comprises a first event of the first plurality of events, a second event of the first plurality of events and a relationship that identifies that the second event of the first plurality of events is based on the first event of the first plurality of events, wherein at least one of the first event and the second event constitutes an anomalous behavior; and comparing the information associated with the one or more observed events with the reference model to determine whether at least one observed event of the one or more observed events matches at least one of the first event of the first plurality of events or the second event of the first plurality of events that constitutes the anomalous behavior is provided.