Malware Spread Identification via Operation History Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware identification techniques fail to accurately track the spread of malware across networks, particularly when a compromised PC copies malware to another PC, leading to incomplete isolation of infected systems.
Innovation Solution
An identification apparatus that utilizes a storage unit to store operation histories, an acquisition unit to gather malware spread information, and an identification unit to trace the intrusion route of malware by analyzing operation logs, generating and identifying direct or indirect spread points within the history.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If only PCs that directly accessed malware files are detected, then the detection process is simple, but the identification accuracy of malware spread range is insufficient
Solution Approach 1:
The system performs preliminary actions by storing operation histories and malware spread information in advance, and pre-identifying intrusion routes through automated analysis of copied files, emails, and web transmissions. This allows comprehensive malware spread tracking without manual investigation, resolving the contradiction between detection accuracy and process complexity.
2Reliability
If malware spread tracking is limited to direct access detection, then the detection system remains simple, but secondary spread through copied files cannot be prevented
Solution Approach 1:
The system implements feedback mechanisms by continuously monitoring operation histories, detecting when malware is copied or transmitted through emails and web, and automatically updating the malware spread information. This closed-loop feedback ensures that secondary spread is detected and contained, improving reliability while managing complexity through automation.
3Measurement precision
If comprehensive operation history analysis is performed to track all malware transmission, then identification accuracy improves, but processing time and computational resources increase
Solution Approach 1:
The system extracts only the essential and relevant operation history data needed for malware spread identification, such as file copy operations, email transmissions, and web communications. By filtering and extracting only critical information rather than analyzing all operations, the system maintains high identification accuracy while reducing processing time and computational overhead.
Data Source
AI summary
There is provided an identification apparatus. A storage unit stores an operation history as a history of an operation executed in at least one information processing apparatus. An acquisition unit acquires malware spread information including information indicating malware. An identification unit identifies, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired by the acquisition unit, generates at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, and identifies, in the operation history, for each of the at least one piece of malware spread information, at least one operation of spreading the malware by setting, as a direct or indirect start point, the malware indicated by the malware spread information.


