Malware Analysis via Virtual-Physical Behavior Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Advanced malware variants can detect virtual machine environments and behave benignly, evading classification and manifesting harmful effects only in actual, vulnerable systems, making it difficult to analyze and detect them effectively.
Innovation Solution
A method involving the initialization of a virtual machine, installation of a malware sample, and analysis of its behavior, followed by booting a physical device from a secondary source, comparing behavior between virtual and physical environments, and using a malware analysis device to analyze the sample in a network-blocked state, mimicking user actions to trigger adverse behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If malware is analyzed in a virtual machine environment, then analysis safety and isolation are improved, but detection accuracy deteriorates because advanced malware can detect the virtual machine environment and behave benignly
Solution Approach 1:
The analysis process is segmented into multiple distinct environments: virtual machine environment for initial safe analysis, physical computing device environment for behavior comparison, and isolated network environment for malware analysis. This segmentation allows the system to address the contradiction by using different environments for different analysis phases, maintaining safety while improving detection accuracy through environmental comparison.
Solution Approach 2:
The patent introduces a new dimension of analysis by comparing malware behavior across different environmental dimensions (virtual machine vs. physical device). This dimensional comparison reveals behavioral differences that indicate malware evasion techniques, thereby improving detection accuracy while maintaining the safety benefits of isolated environments.
2Measurement precision
If malware is analyzed in a physical computing device environment, then detection accuracy is improved by catching benign behavior, but analysis safety and isolation deteriorate due to potential system compromise
Solution Approach 1:
An isolated network environment serves as an intermediary between the physical computing device and the external network. This intermediary allows the physical device to analyze malware with high accuracy while the network isolation prevents actual system compromise, thus resolving the contradiction between detection accuracy and analysis safety.
Solution Approach 2:
The patent creates a copy of the physical computing device environment through virtual machine snapshots and network isolation. This allows safe replication of the physical analysis environment without actual physical compromise, maintaining both detection accuracy and analysis safety simultaneously.
3Adaptability or versatility
If advanced malware detects it is in a virtual machine environment, then malware evasion capability is improved, but analysis effectiveness deteriorates as the malware takes no action or only benign actions
Solution Approach 1:
The analysis system dynamically transitions between different environments (virtual machine to physical device) based on the malware's detected behavior. This dynamic approach allows the system to adapt to malware evasion capabilities by changing the analysis environment, thereby maintaining analysis effectiveness despite advanced malware detection and evasion techniques.
4Measurement precision
If multiple analysis environments are used to compare malware behavior, then detection accuracy is improved, but system complexity and resource requirements increase
Solution Approach 1:
The virtual machine environment serves multiple functions: initial safe analysis, behavior comparison with physical devices, and network isolation during analysis. This multi-functionality reduces the need for separate dedicated systems for each function, thereby improving detection accuracy while limiting the increase in overall system complexity.
Data Source
AI summary
Methods of analyzing malware and other suspicious files are presented, where some embodiments include analyzing the behavior of a first malware sample on both a virtual machine and a physical computing device, the physical device having been booted from a secondary boot source, and determining whether the behavior of the malware sample was different on the virtual machine and the physical computing device. In certain embodiments, a notification indicating that the behavior was different may be generated. In other embodiments, a malware analysis computing device that is configured to receive a base hard drive image may be network booted, and the behavior of the malware sample on the malware analysis computing device may be analyzed. In certain embodiments, a malware-infected hard drive image may then be copied off the malware analysis computing device.


