Runtime Malware Detection via Dynamic API Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Android malware detection systems are ineffective against evolving malware due to reliance on static analysis, which fails to detect runtime updates and obfuscated malware, and cloud-based solutions can be bypassed by delayed activation strategies, leading to high resource consumption and false positives.

Innovation Solution

A dynamic malware detection system that uses machine learning at both device and cloud levels to monitor runtime API calls, intercepting critical functions and assessing data for malicious activity without repackaging or resigning applications, thereby reducing CPU and battery overhead and minimizing false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If static analysis is used for malware detection, then detection speed is improved, but detection accuracy deteriorates because malware updates at runtime and uses obfuscation

Engineering Contradiction:
Improvedetection speedVSAvoiddetection accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent transitions from static analysis to dynamic runtime analysis. The system instruments the runtime environment to monitor API calls, method invocations, and control flow during actual execution. This dynamic approach captures malware behavior as it occurs, preventing obfuscation techniques from hiding malicious intent while maintaining efficient detection through event-driven monitoring.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces traditional mechanical signature-matching approaches with a data-driven machine learning system. The ML model analyzes runtime behavior patterns, API call sequences, and control flow characteristics to detect malware. This substitution enables the system to identify novel and obfuscated malware based on behavioral patterns rather than static signatures, significantly improving detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If cloud-based malware detection is used, then detection capability is improved, but malware can bypass using time delay activation strategies

Engineering Contradiction:
Improvedetection capabilityVSAvoidbypass resistance
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements preliminary instrumentation of the runtime environment during application installation or loading. Detection hooks are pre-established in the runtime library, creating a persistent monitoring framework that activates immediately when the application runs. This preliminary setup ensures that even time-delayed malicious behaviors are captured from the moment execution begins, preventing bypass strategies from succeeding.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary instrumentation layer between the application and the runtime environment. This intermediary captures API calls and control flow information before they execute, creating a detailed trace of application behavior. The machine learning analysis operates on this intercepted data, enabling reliable detection of malicious patterns while maintaining the ability to distinguish between legitimate and malicious applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive runtime monitoring is implemented, then malware detection accuracy is improved, but CPU and battery overhead increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidbattery overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements selective monitoring of critical API calls and control flow events rather than exhaustive logging of all runtime operations. The instrumentation focuses on high-value indicators of malicious behavior, such as unauthorized file access, network communications, and system configuration changes. This partial monitoring approach maintains high detection accuracy while significantly reducing the computational overhead and energy consumption compared to comprehensive monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent enables the machine learning model to operate efficiently on-device using local computation and cached behavior patterns. The system learns from historical runtime data and applies this knowledge to rapidly evaluate current application behavior without requiring constant cloud communication. This self-service capability reduces CPU overhead and battery consumption while maintaining high detection accuracy through localized intelligent analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11568051B2Malicious object detection in a runtime environment
Publication Date: 2023.01.31 INTEL CORP
  • US11568051B2 patent drawing
  • US11568051B2 patent drawing
  • US11568051B2 patent drawing

AI summary

A malicious object detection system for use in managed runtime environments includes a check circuit to receive call information generated by an application, such as an Android application. A machine learning circuit coupled to the check circuit applies a machine learning model to assess the information and/or data included in the call and detect the presence of a malicious object, such as malware or a virus, in the application generating the call. The machine learning model may include a global machine learning model distributed across a number of devices, a local machine learning model based on use patterns of a particular device, or combinations thereof. A graphical user interface management circuit halts execution of applications containing malicious objects and generates a user perceptible output.