Malware Sample Selection via Clustering for Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional sandboxing methods struggle to detect advanced malware due to evasion techniques, leading to increased costs and limited intelligence gathering, while also lacking context and structure for effective clustering and differentiation of malware samples.
Innovation Solution
Combining sandboxing results with traffic analysis to create clusters of malware samples based on shared artifacts and communication behavior, using a clustering algorithm to identify representative samples for further analysis, thereby reducing computational resources and enhancing detection capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional sandboxing is used to detect malware, then detection capability is provided, but advanced malware can evade detection due to sandbox awareness
Solution Approach 1:
The patent segments malware analysis into multiple independent sandbox environments with different configurations and resource profiles. By dividing the analysis process across multiple sandboxes rather than relying on a single conventional sandbox, the system prevents malware from evading detection through sandbox awareness, as each sandbox presents a unique environment that malware cannot predict or adapt to uniformly.
Solution Approach 2:
The patent introduces a new dimension to malware detection by analyzing malware behavior across multiple sandbox environments simultaneously. Instead of relying on single-environment detection, the system evaluates malware performance across diverse sandbox configurations, adding environmental variability as an additional detection dimension that undermines malware's ability to evade through sandbox detection techniques.
2Loss of information
If comprehensive malware analysis is performed on all samples, then detailed intelligence is gathered, but computational resources are excessively consumed
Solution Approach 1:
The patent extracts and analyzes only the most critical and representative malware samples for comprehensive intelligence gathering. By identifying and focusing analysis on high-value samples that exhibit distinctive or dangerous behaviors, the system obtains sufficient malware intelligence without the need to perform exhaustive analysis on every sample, thereby reducing computational resource consumption while maintaining effective threat detection capability.
Solution Approach 2:
The patent applies partial action by performing comprehensive analysis on a selective subset of malware samples rather than all samples. This approach provides adequate malware intelligence for detection purposes while avoiding the excessive computational resource consumption that would result from analyzing every sample in full detail, achieving an optimal balance between intelligence gathering and resource usage.
3Ease of operation
If malware samples are analyzed individually in isolation, then analysis simplicity is maintained, but contextual understanding of malware families is lost
Solution Approach 1:
The patent merges individual malware sample analyses by grouping samples into families based on shared characteristics and behavioral patterns observed across multiple sandbox environments. This combining approach maintains the simplicity of individual analysis while adding contextual understanding through family-level classification, allowing the system to leverage both isolated sample evaluation and collective pattern recognition for improved detection accuracy.
Data Source
AI summary
In one embodiment, a method includes creating a set of network related indicators of compromise at a computing device, the set associated with a malicious network operation, identifying at the computing device, samples comprising at least one of the indicators of compromise in the set, creating sub-clusters of the samples at the computing device, and selecting at the computing device, one of the samples from the sub-clusters for additional analysis, wherein results of the analysis provide information for use in malware detection. An apparatus and logic are also disclosed herein.


