Malware Spread Identification via Operation History Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware identification techniques fail to accurately track the spread of malware across networks, particularly when a compromised PC copies malware to another PC, leading to incomplete isolation of infected systems.

Innovation Solution

An identification apparatus that utilizes a storage unit to store operation histories, an acquisition unit to gather malware spread information, and an identification unit to trace the intrusion route of malware by analyzing operation logs, generating and identifying direct or indirect spread points within the history.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If only PCs that directly accessed malware files are detected, then the detection process is simple, but the identification accuracy of malware spread range is insufficient

Engineering Contradiction:
Improveidentification accuracy of malware spread rangeVSAvoidcomplexity of detection process
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by storing operation histories and malware spread information in advance, and pre-identifying intrusion routes through automated analysis of copied files, emails, and web transmissions. This allows comprehensive malware spread tracking without manual investigation, resolving the contradiction between detection accuracy and process complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If malware spread tracking is limited to direct access detection, then the detection system remains simple, but secondary spread through copied files cannot be prevented

Engineering Contradiction:
Improveeffectiveness of malware containmentVSAvoidcomplexity of spread tracking
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms by continuously monitoring operation histories, detecting when malware is copied or transmitted through emails and web, and automatically updating the malware spread information. This closed-loop feedback ensures that secondary spread is detected and contained, improving reliability while managing complexity through automation.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive operation history analysis is performed to track all malware transmission, then identification accuracy improves, but processing time and computational resources increase

Engineering Contradiction:
Improveaccuracy of malware spread identificationVSAvoidtime for malware analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts only the essential and relevant operation history data needed for malware spread identification, such as file copy operations, email transmissions, and web communications. By filtering and extracting only critical information rather than analyzing all operations, the system maintains high identification accuracy while reducing processing time and computational overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10382477B2Identification apparatus, control method therefor, and storage medium
Publication Date: 2019.08.13 CANON DENSHI KK
  • US10382477B2 patent drawing
  • US10382477B2 patent drawing
  • US10382477B2 patent drawing

AI summary

There is provided an identification apparatus. A storage unit stores an operation history as a history of an operation executed in at least one information processing apparatus. An acquisition unit acquires malware spread information including information indicating malware. An identification unit identifies, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired by the acquisition unit, generates at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, and identifies, in the operation history, for each of the at least one piece of malware spread information, at least one operation of spreading the malware by setting, as a direct or indirect start point, the malware indicated by the malware spread information.