Malware Source Tracing via Memory State Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-virus software is ineffective against unknown malware, allowing it to propagate unchecked in networks until updates are made, leading to rapid spread and potential global pandemics.

Innovation Solution

A method and system that trace the spread of malware by collecting and analyzing memory state data from infected devices, using a database to identify infected devices and map the malware's origin, with anti-virus software reporting suspicious data through an API to a server for storage and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anti-virus software uses signature-based detection, then known malware can be identified and removed, but unknown malware cannot be detected and propagates unchecked

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidability to detect unknown malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting memory state data from infected devices before the malware can propagate further. The anti-virus software captures and transmits memory dumps to a server for analysis, enabling proactive identification and tracking of unknown malware strains before they spread widely through the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary server system that receives, stores, and analyzes memory state data from multiple infected devices. This intermediary infrastructure enables centralized processing of malware samples, allowing researchers to identify patterns and characteristics of unknown malware without requiring real-time detection at each individual device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If anti-virus software waits for updates to identify new malware, then current detection accuracy is maintained, but malware spreads exponentially during the update period

Engineering Contradiction:
Improvemalware identification accuracyVSAvoidtime delay in malware detection
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by immediately collecting and transmitting memory state data when malware infection is detected, before waiting for signature updates. The server analyzes the captured memory dumps in real-time, enabling rapid identification of unknown malware strains and their propagation paths without delaying detection for future updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the server analyzes memory state data and provides information back to the anti-virus software and users. This feedback loop enables continuous learning and improvement of detection capabilities, allowing the system to identify new malware strains faster and more accurately without waiting for manual signature updates.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If the system collects detailed memory state data from all infected devices, then malware tracing accuracy is improved, but system resources and network bandwidth are consumed

Engineering Contradiction:
Improvemalware source identification accuracyVSAvoidamount of data to be processed
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the essential information needed for malware analysis from the complete memory state data. The anti-virus software selectively captures and transmits specific memory dumps and metadata to the server, filtering out unnecessary data while preserving critical information for identifying malware characteristics and propagation paths.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the data collection and analysis process into distinct phases: initial memory state capture at infected devices, selective data transmission to the server, and targeted analysis of specific memory regions. This segmentation enables efficient processing by focusing resources on the most informative data elements rather than processing entire memory contents.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7434261B2System and method of identifying the source of an attack on a computer network
Publication Date: 2008.10.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7434261B2 patent drawing
  • US7434261B2 patent drawing
  • US7434261B2 patent drawing

AI summary

The present invention provides a system and method of tracing the spread of computer malware in a communication network. One aspect of the present invention is a method that traces the spread of computer malware in a communication network. When suspicious data characteristic of malware is identified in a computing device connected to the communication network, the method causes data that describes the state of the computing device to be stored in a database. After a specific attack against the communication network is confirmed, computing devices that are infected with the malware are identified. Then, the spread of the malware between computing devices in the communication network is traced back to a source.