Malware Variant Identification via Metadata Similarity Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security methods are inefficient and prone to human error in identifying variants of malicious software due to polymorphism, which allows attackers to evade detection by modifying software while preserving its malicious functionality.

Innovation Solution

The system automatically collects and compares metadata attributes from security agents on endpoint computing systems to identify related samples, designating current samples as related to previously identified samples based on similarity analysis, and performs security actions to protect users from malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security vendors manually code each detected variant as malware, then they can identify malicious software, but the process is inefficient, not comprehensive, and prone to human error

Engineering Contradiction:
Improveaccuracy of malware identificationVSAvoidefficiency of variant identification
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service by allowing the malware identification system to automatically identify and categorize variants through polymorphic analysis, eliminating the need for manual coding of each variant. The system performs self-updating through automatic learning from new samples, and self-configuration by adapting to different polymorphic techniques without human intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of coding variants with an automated computational system that uses polymorphic analysis, machine learning, and pattern recognition algorithms to automatically identify and categorize malware variants, thereby eliminating human error and significantly improving efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If attackers modify software through polymorphism to avoid detection, then they can preserve malicious functionality, but security vendors struggle to keep up with modifications

Engineering Contradiction:
Improveability to detect modified variantsVSAvoidtime to identify new variants
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-establishing polymorphic analysis capabilities and pattern recognition frameworks that can proactively detect variants before they become widespread threats. The system continuously monitors and analyzes malware samples in advance, building a knowledge base of polymorphic techniques that enables rapid identification of new variants as they emerge.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by creating a living, evolving system that continuously adapts to new polymorphic techniques. The automated analysis system dynamically updates its detection rules and patterns based on newly analyzed samples, allowing it to keep pace with rapidly changing malware variants without manual intervention.

Inventive Principle:
Principle #15Dynamics

3Reliability

If security vendors attempt to manually code each detected variant, then they can maintain security policies, but the process is inefficient and prone to human error

Engineering Contradiction:
Improveaccuracy of security policy applicationVSAvoidcomplexity of variant management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements universality by creating a single automated platform that performs multiple functions: polymorphic analysis, variant identification, pattern recognition, and security policy application. This multi-functional system replaces multiple separate manual processes, reducing overall system complexity while improving reliability through consistent automated execution of security policies across all variant types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9571509B1Systems and methods for identifying variants of samples based on similarity analysis
Publication Date: 2017.02.14 CA TECH INC
  • US9571509B1 patent drawing
  • US9571509B1 patent drawing
  • US9571509B1 patent drawing

AI summary

A computer-implemented method for identifying variants of samples based on similarity analysis may include (1) collecting, from security agents on endpoint computing systems, metadata attributes that describe samples identified by the security agents over an initial period of time, (2) collecting metadata attributes that describe a current sample identified after the initial period of time, (3) comparing at least two of the metadata attributes that describe the current sample with corresponding metadata attributes of the samples identified over the initial period of time, (4) designating the current sample as related to another sample from the samples identified over the initial period of time based on the comparison of the two metadata attributes, and (5) performing a security action to protect a user from malware based on the designation of the current sample as related to the other sample. Various other methods, systems, and computer-readable media are also disclosed.