Runtime Malware Detection via Dynamic API Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Android malware detection systems are ineffective against evolving malware due to reliance on static analysis, which fails to detect runtime updates and obfuscated malware, and cloud-based solutions can be bypassed by delayed activation strategies, leading to high resource consumption and false positives.
Innovation Solution
A dynamic malware detection system that uses machine learning at both device and cloud levels to monitor runtime API calls, intercepting critical functions and assessing data for malicious activity without repackaging or resigning applications, thereby reducing CPU and battery overhead and minimizing false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If static analysis is used for malware detection, then detection speed is improved, but detection accuracy deteriorates because malware updates at runtime and uses obfuscation
Solution Approach 1:
The patent transitions from static analysis to dynamic runtime analysis. The system instruments the runtime environment to monitor API calls, method invocations, and control flow during actual execution. This dynamic approach captures malware behavior as it occurs, preventing obfuscation techniques from hiding malicious intent while maintaining efficient detection through event-driven monitoring.
Solution Approach 2:
The patent replaces traditional mechanical signature-matching approaches with a data-driven machine learning system. The ML model analyzes runtime behavior patterns, API call sequences, and control flow characteristics to detect malware. This substitution enables the system to identify novel and obfuscated malware based on behavioral patterns rather than static signatures, significantly improving detection accuracy.
2Measurement precision
If cloud-based malware detection is used, then detection capability is improved, but malware can bypass using time delay activation strategies
Solution Approach 1:
The patent implements preliminary instrumentation of the runtime environment during application installation or loading. Detection hooks are pre-established in the runtime library, creating a persistent monitoring framework that activates immediately when the application runs. This preliminary setup ensures that even time-delayed malicious behaviors are captured from the moment execution begins, preventing bypass strategies from succeeding.
Solution Approach 2:
The patent introduces an intermediary instrumentation layer between the application and the runtime environment. This intermediary captures API calls and control flow information before they execute, creating a detailed trace of application behavior. The machine learning analysis operates on this intercepted data, enabling reliable detection of malicious patterns while maintaining the ability to distinguish between legitimate and malicious applications.
3Measurement precision
If comprehensive runtime monitoring is implemented, then malware detection accuracy is improved, but CPU and battery overhead increases
Solution Approach 1:
The patent implements selective monitoring of critical API calls and control flow events rather than exhaustive logging of all runtime operations. The instrumentation focuses on high-value indicators of malicious behavior, such as unauthorized file access, network communications, and system configuration changes. This partial monitoring approach maintains high detection accuracy while significantly reducing the computational overhead and energy consumption compared to comprehensive monitoring.
Solution Approach 2:
The patent enables the machine learning model to operate efficiently on-device using local computation and cached behavior patterns. The system learns from historical runtime data and applies this knowledge to rapidly evaluate current application behavior without requiring constant cloud communication. This self-service capability reduces CPU overhead and battery consumption while maintaining high detection accuracy through localized intelligent analysis.
Data Source
AI summary
A malicious object detection system for use in managed runtime environments includes a check circuit to receive call information generated by an application, such as an Android application. A machine learning circuit coupled to the check circuit applies a machine learning model to assess the information and/or data included in the call and detect the presence of a malicious object, such as malware or a virus, in the application generating the call. The machine learning model may include a global machine learning model distributed across a number of devices, a local machine learning model based on use patterns of a particular device, or combinations thereof. A graphical user interface management circuit halts execution of applications containing malicious objects and generates a user perceptible output.


