Malware Detection Using Reference Model Relationship Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber security systems fail to effectively identify relationships between malicious exploits and generate reference models for comparison with future events, leading to incomplete threat detection and prevention.
Innovation Solution
A malware detection and visualization system that uses machine learning to generate reference models from observed data, allowing for real-time and forensic analysis of network traffic and endpoint device data to detect and visualize potential malware threats by comparing incoming data with known malicious behaviors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If current threat detection systems present exploit information in a list format, then security personnel receive information about uncovered exploits, but the systems fail to identify relationships between exploits that would help understand potential effects
Solution Approach 1:
The system performs preliminary analysis by generating reference models from observed exploits and malicious behaviors before comparison with new events. This advance preparation enables the system to identify relationships between exploits and predict potential effects, rather than merely listing detected exploits after the fact.
Solution Approach 2:
The system creates simplified representations (reference models) that copy the essential characteristics and relationships of complex exploit behaviors. These reference models capture the structural patterns of malicious activities, enabling efficient comparison and relationship identification without requiring analysis of the full complexity of each individual exploit.
2Measurement precision
If the system generates reference models from observed exploits and malicious behaviors, then exploit detection accuracy improves, but the processing time and computational resources increase
Solution Approach 1:
The system extracts only the essential and relevant features from observed exploits and malicious behaviors to create reference models. By taking out only the critical characteristics needed for detection rather than analyzing complete exploit data, the system achieves high detection accuracy while reducing computational overhead and processing time.
Solution Approach 2:
The system transforms raw exploit data into standardized reference model parameters that facilitate efficient comparison. By changing the representation parameters of exploit data into structured models with defined attributes and relationships, the system enables faster matching and detection while maintaining high precision.
3Loss of information
If the system provides detailed visual representation of exploit relationships, then security personnel can better understand malicious activities, but the information presentation complexity increases
Solution Approach 1:
The system segments the complex web of exploit relationships into discrete, manageable visual elements representing different aspects of malicious activities. By dividing the overall exploit structure into separate visual components (such as individual malicious events, their relationships, and potential effects), the system enables security personnel to understand relationships without being overwhelmed by complexity.
Data Source
AI summary
According to one embodiment, a computerized method comprises, accessing information associated with one or more observed events, wherein one or more of the observed events constitutes an anomalous behavior; accessing a reference model based on a first plurality of events, the reference model comprises a first event of the first plurality of events, a second event of the first plurality of events and a relationship that identifies that the second event of the first plurality of events is based on the first event of the first plurality of events, wherein at least one of the first event and the second event constitutes an anomalous behavior; and comparing the information associated with the one or more observed events with the reference model to determine whether at least one observed event of the one or more observed events matches at least one of the first event of the first plurality of events or the second event of the first plurality of events that constitutes the anomalous behavior is provided.


