Shadow Sandbox Malware Detection via Virtual Machine Replication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices are vulnerable to malware exploitation and deception, making it difficult to detect and prevent malicious software that leverages vulnerabilities or deceives users, especially as malware can be designed to evade detection and target specific environments.

Innovation Solution

A shadow sandbox is maintained by monitoring a protected computing system for change and risk events, with a virtual machine replica that updates and executes risk events to determine their maliciousness, allowing for real-time detection and blocking of malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a virtual machine replica is maintained and updated through all change events to accurately reflect the target computing environment, then malware detection accuracy is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates and maintains a virtual machine replica (shadow sandbox) that copies the essential state and configuration of the target computing environment. This copy allows malware analysis to be performed in isolation without affecting the real system, enabling accurate detection while managing complexity through virtualization abstraction

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system segments the computing environment into a real target system and a virtual replica, allowing independent monitoring and analysis. The shadow sandbox is maintained separately through change event monitoring, enabling precise malware detection in the virtual environment without compromising the integrity or increasing the complexity burden on the production system

Inventive Principle:
Principle #1Segmentation

2Reliability

If risk events are executed on the virtual machine replica for analysis, then malware detection capability is improved, but processing time increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining the virtual machine replica in sync with the target environment through change event monitoring. When a risk event is detected, the virtual machine is already prepared and can execute the event for analysis without requiring full system reconfiguration or setup, reducing processing time while maintaining detection reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The virtual machine replica acts as an intermediary that can safely execute risk events and malware in isolation. This mediator allows the system to analyze potentially harmful code without time-critical operations on the real system, enabling thorough malware detection while minimizing impact on production processing time

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If the shadow sandbox is maintained in sync with all changes to the target computing environment, then detection accuracy is improved, but computational resources are consumed

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies local quality by monitoring and replicating only specific change events that are relevant to malware detection rather than copying every system change. This selective approach maintains detection accuracy for security-critical changes while reducing unnecessary computational overhead from replicating irrelevant system modifications

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10474819B2Methods and systems for maintaining a sandbox for use in malware detection
Publication Date: 2019.11.12 VMWARE INC
  • US10474819B2 patent drawing
  • US10474819B2 patent drawing
  • US10474819B2 patent drawing

AI summary

A shadow sandbox is maintained for malware detection. The shadow sandbox is a virtual machine replica of a target computing environment from a protected computing system. The shadow sandbox is maintained through all change events that occur to the target computing environment. The described systems and methods of detecting or preventing malware execution include maintaining a virtual machine replica of a target computing system by monitoring the target computing system for a plurality of possible events, the plurality of possible events including change events and risk events, detecting a change event on the target computing system, and updating the virtual machine based on the detected change event. The described systems and methods detect a risk event on the target computing system, execute the risk event on the virtual machine, and determine whether the risk event is malicious based on observation of execution of the risk event on the virtual machine.