Sandbox Malware Detection via Node Copying

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current sandbox environments face challenges in replicating the execution environment of target computers, leading to incomplete malware behavior analysis due to misconfiguration, which increases maintenance costs and complexity, especially in targeted attacks.

Innovation Solution

Generating a copy of a node that includes data storage content and hardware layout data to configure a sandbox environment, allowing for the execution of electronic files or URLs in a realistic manner, enabling reliable malware analysis and reducing operational complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a sandbox environment is configured to replicate target computer execution environments, then malware analysis reliability is improved, but device complexity and maintenance cost increase

Engineering Contradiction:
Improvemalware analysis reliabilityVSAvoidsandbox environment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a copy of the target computer's execution environment (including hardware layout, device configuration, and data storage content) to configure the sandbox. This copy allows the sandbox to replicate the target environment's behavior without maintaining the actual complex target system, thereby improving analysis reliability while reducing operational complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the target environment into a sandbox configuration by changing parameters such as isolating processes, emulating hardware devices, and reproducing file system structures. These parameter changes enable the sandbox to maintain realistic execution environments while operating as a simplified, controlled system.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If the sandbox environment is continuously updated to match modern software requirements, then malware detection accuracy is improved, but maintenance cost and time increase

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidmaintenance time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by capturing and storing the target environment's configuration, hardware layout, and data storage content before the malware analysis begins. This pre-configured copy eliminates the need for continuous updates during analysis, allowing the sandbox to maintain accurate detection capabilities without ongoing maintenance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By creating a static copy of the target environment, the patent freezes the configuration at a specific point in time. This copy can be reused for multiple analysis scenarios without requiring updates, thereby maintaining detection accuracy while eliminating continuous maintenance requirements.

Inventive Principle:
Principle #26Copying

3Reliability

If the sandbox replicates targeted attack configurations, then detection of targeted attacks is improved, but the complexity of maintaining multiple environment configurations increases

Engineering Contradiction:
Improvetargeted attack detection reliabilityVSAvoidenvironment configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a copy of the specific target environment configuration that was compromised in targeted attacks. This copy includes the exact hardware layout, device configurations, and data storage content of the compromised system, enabling reliable detection of attack-specific behaviors without maintaining multiple different environment configurations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments the sandbox environment into distinct components (process isolation, hardware emulation, file system reproduction) that can be independently configured. This segmentation allows the sandbox to replicate specific targeted attack configurations without managing the complexity of entire environment configurations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11010473B2Method of detecting malware in a sandbox environment
Publication Date: 2021.05.18 F SECURE CORP
  • US11010473B2 patent drawing
  • US11010473B2 patent drawing
  • US11010473B2 patent drawing

AI summary

There are provided measures for enabling detecting malware. A method includes generating a copy of a first node, configuring a sandbox environment by using the generated copy, executing an electronic file or a URL in the sandbox environment configured with the copy, providing a result of the malware analysis of the electronic file or the URL, identifying the electronic file or the URL as malicious or suspicious on the basis of the provided result, and taking further action for protecting the first node from the electronic file or the URL identified as malicious or suspicious.