Malware Sample Selection via Clustering for Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional sandboxing methods struggle to detect advanced malware due to evasion techniques, leading to increased costs and limited intelligence gathering, while also lacking context and structure for effective clustering and differentiation of malware samples.

Innovation Solution

Combining sandboxing results with traffic analysis to create clusters of malware samples based on shared artifacts and communication behavior, using a clustering algorithm to identify representative samples for further analysis, thereby reducing computational resources and enhancing detection capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional sandboxing is used to detect malware, then detection capability is provided, but advanced malware can evade detection due to sandbox awareness

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidmalware evasion capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments malware analysis into multiple independent sandbox environments with different configurations and resource profiles. By dividing the analysis process across multiple sandboxes rather than relying on a single conventional sandbox, the system prevents malware from evading detection through sandbox awareness, as each sandbox presents a unique environment that malware cannot predict or adapt to uniformly.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to malware detection by analyzing malware behavior across multiple sandbox environments simultaneously. Instead of relying on single-environment detection, the system evaluates malware performance across diverse sandbox configurations, adding environmental variability as an additional detection dimension that undermines malware's ability to evade through sandbox detection techniques.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If comprehensive malware analysis is performed on all samples, then detailed intelligence is gathered, but computational resources are excessively consumed

Engineering Contradiction:
Improvemalware intelligence gatheringVSAvoidcomputational resource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent extracts and analyzes only the most critical and representative malware samples for comprehensive intelligence gathering. By identifying and focusing analysis on high-value samples that exhibit distinctive or dangerous behaviors, the system obtains sufficient malware intelligence without the need to perform exhaustive analysis on every sample, thereby reducing computational resource consumption while maintaining effective threat detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by performing comprehensive analysis on a selective subset of malware samples rather than all samples. This approach provides adequate malware intelligence for detection purposes while avoiding the excessive computational resource consumption that would result from analyzing every sample in full detail, achieving an optimal balance between intelligence gathering and resource usage.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If malware samples are analyzed individually in isolation, then analysis simplicity is maintained, but contextual understanding of malware families is lost

Engineering Contradiction:
Improveanalysis process simplicityVSAvoidmalware family context
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent merges individual malware sample analyses by grouping samples into families based on shared characteristics and behavioral patterns observed across multiple sandbox environments. This combining approach maintains the simplicity of individual analysis while adding contextual understanding through family-level classification, allowing the system to leverage both isolated sample evaluation and collective pattern recognition for improved detection accuracy.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10015192B1Sample selection for data analysis for use in malware detection
Publication Date: 2018.07.03 CISCO TECHNOLOGY INC
  • US10015192B1 patent drawing
  • US10015192B1 patent drawing
  • US10015192B1 patent drawing

AI summary

In one embodiment, a method includes creating a set of network related indicators of compromise at a computing device, the set associated with a malicious network operation, identifying at the computing device, samples comprising at least one of the indicators of compromise in the set, creating sub-clusters of the samples at the computing device, and selecting at the computing device, one of the samples from the sub-clusters for additional analysis, wherein results of the analysis provide information for use in malware detection. An apparatus and logic are also disclosed herein.