Malware Variant Identification via Metadata Similarity Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security methods are inefficient and prone to human error in identifying variants of malicious software due to polymorphism, which allows attackers to evade detection by modifying software while preserving its malicious functionality.
Innovation Solution
The system automatically collects and compares metadata attributes from security agents on endpoint computing systems to identify related samples, designating current samples as related to previously identified samples based on similarity analysis, and performs security actions to protect users from malware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security vendors manually code each detected variant as malware, then they can identify malicious software, but the process is inefficient, not comprehensive, and prone to human error
Solution Approach 1:
The system enables self-service by allowing the malware identification system to automatically identify and categorize variants through polymorphic analysis, eliminating the need for manual coding of each variant. The system performs self-updating through automatic learning from new samples, and self-configuration by adapting to different polymorphic techniques without human intervention.
Solution Approach 2:
The patent replaces the mechanical manual process of coding variants with an automated computational system that uses polymorphic analysis, machine learning, and pattern recognition algorithms to automatically identify and categorize malware variants, thereby eliminating human error and significantly improving efficiency.
2Adaptability or versatility
If attackers modify software through polymorphism to avoid detection, then they can preserve malicious functionality, but security vendors struggle to keep up with modifications
Solution Approach 1:
The system performs preliminary action by pre-establishing polymorphic analysis capabilities and pattern recognition frameworks that can proactively detect variants before they become widespread threats. The system continuously monitors and analyzes malware samples in advance, building a knowledge base of polymorphic techniques that enables rapid identification of new variants as they emerge.
Solution Approach 2:
The patent implements dynamics by creating a living, evolving system that continuously adapts to new polymorphic techniques. The automated analysis system dynamically updates its detection rules and patterns based on newly analyzed samples, allowing it to keep pace with rapidly changing malware variants without manual intervention.
3Reliability
If security vendors attempt to manually code each detected variant, then they can maintain security policies, but the process is inefficient and prone to human error
Solution Approach 1:
The system implements universality by creating a single automated platform that performs multiple functions: polymorphic analysis, variant identification, pattern recognition, and security policy application. This multi-functional system replaces multiple separate manual processes, reducing overall system complexity while improving reliability through consistent automated execution of security policies across all variant types.
Data Source
AI summary
A computer-implemented method for identifying variants of samples based on similarity analysis may include (1) collecting, from security agents on endpoint computing systems, metadata attributes that describe samples identified by the security agents over an initial period of time, (2) collecting metadata attributes that describe a current sample identified after the initial period of time, (3) comparing at least two of the metadata attributes that describe the current sample with corresponding metadata attributes of the samples identified over the initial period of time, (4) designating the current sample as related to another sample from the samples identified over the initial period of time based on the comparison of the two metadata attributes, and (5) performing a security action to protect a user from malware based on the designation of the current sample as related to the other sample. Various other methods, systems, and computer-readable media are also disclosed.


