Software Gene-Based Malware Classification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional malware and unwanted software detection methods rely on signature-based approaches, which are ineffective against rapidly evolving and variant malware, leading to high false positive rates and potential system infections before definitions are released, and fail to proactively classify software before damage is caused.

Innovation Solution

The method involves identifying functional blocks and properties of software, extracting 'genes' that describe specific functionalities, and matching these against classifications defined from groupings of genes to classify software without requiring up-to-date malware definitions, using a system that includes a malware detection engine and a library of gene information for immediate and scheduled scanning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based detection methods are used, then known malware can be detected, but rapidly evolving and variant malware cannot be detected, leading to high false positive rates and potential system infections

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect variant malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments malware into functional blocks and identifies specific genes within those blocks. Instead of treating malware as a single signature entity, the system breaks it down into discrete functional components (genes) that can be independently identified and classified. This segmentation allows the system to detect variant malware by recognizing common functional patterns across different malware families while maintaining the ability to distinguish between benign and malicious software.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary classification of software by identifying functional blocks and genes before execution or before the malware can cause damage. By proactively analyzing software characteristics and matching genes against known classifications in advance, the system can prevent infections before they occur, rather than relying on reactive signature updates after malware is released.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If heuristics techniques are used to identify unknown viruses, then detection capability is improved, but false positive rates increase

Engineering Contradiction:
Improvedetection of unknown malwareVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by focusing analysis on specific functional blocks and genes within software rather than applying blanket heuristic rules to entire programs. By identifying and analyzing specific local characteristics (functional blocks with particular genes) rather than overall program properties, the system achieves more precise classification with fewer false positives.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameters of analysis from traditional heuristic properties to specific functional block characteristics and gene presence/absence. By transforming the detection parameters from general behavioral heuristics to specific functional identifiers, the system maintains high detection capability while reducing false positives through more precise parameter matching.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If behavior based technology is used, then unknown malware can be detected, but extensive user interaction is required to authorize false positives

Engineering Contradiction:
Improvedetection of malicious behaviorVSAvoiduser interaction requirement
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically classifying software through gene identification and matching against predefined classifications. The automated classification process reduces the need for user interaction by providing confident classifications based on objective gene presence/absence criteria, eliminating or reducing the need for users to authorize each detection decision.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of user interaction and manual authorization with an automated computational system that classifies software based on gene matching. By substituting automated gene-based classification for manual user decision-making, the system maintains behavioral detection capabilities while eliminating the operational burden of user interaction.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Device complexity

If traditional signature-based approaches are used, then detection is simple, but proactive classification before damage cannot be achieved

Engineering Contradiction:
Improvedetection system simplicityVSAvoidtime to release definitions
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system performs preliminary classification by identifying functional blocks and genes before malware can propagate or cause damage. By proactively analyzing software characteristics and matching genes against known classifications in advance, the system can prevent infections before they occur, rather than relying on reactive signature updates after malware is released.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments malware into functional blocks and identifies specific genes within those blocks. This segmentation enables the system to build a library of gene classifications that can be rapidly matched against new software, providing both proactive detection capability and simplified ongoing operation through pre-established classification frameworks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8261344B2Method and system for classification of software using characteristics and combinations of such characteristics
Publication Date: 2012.09.04 SOPHOS LTD
  • US8261344B2 patent drawing
  • US8261344B2 patent drawing
  • US8261344B2 patent drawing

AI summary

Certain embodiments of the present invention provide methods and systems for software classification. Certain embodiments provide a method for identification of malware. Certain embodiments provide a method for identification of unwanted software. The method includes identifying one or more functional blocks and/or properties of software. The method further includes identifying genes in the functional blocks and/or properties. The method also includes matching the resulting list of genes against one or more combinations of classifications of groupings of genes. Additionally, the method includes classifying the software. Certain embodiments provide a method for generating classifications. The method includes identifying functional blocks and/or properties. Furthermore, the method includes combining a plurality of genes to form a classification.