Steganography Detection System for Media Files

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for detecting steganography-based malware attacks are largely manual, labor-intensive, and ineffective in preventing such attacks in real-time, often requiring visual inspection of binary files and failing to detect steganographically hidden malware until after damage has been done.

Innovation Solution

A stegano-based detection and remediation system that performs real-time steganalysis on probabilistically filtered media files, using a media file interceptor, classifier, steganalysis operator, and remediator to assign reputation ratings and disrupt steganographic components without compromising the carrier file, thereby proactively identifying and mitigating steganographically hidden malware and confidential information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual detection techniques are used to identify steganographically hidden malware, then detection accuracy can be improved through visual inspection of binary data, but detection speed and productivity deteriorate due to labor-intensive processes

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces manual visual inspection (mechanical human analysis) with automated steganalysis algorithms and machine learning models. The system uses computational methods to detect steganographically hidden malware in media files, substituting human analysts with automated processing that maintains high detection accuracy while dramatically improving processing speed and productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces intermediate processing layers including feature extraction modules, steganalysis operators, and classification systems that act as intermediaries between the raw media files and final detection results. These intermediary components break down the complex detection task into manageable stages, enabling automated high-speed processing while maintaining the precision previously achievable only through manual inspection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive steganalysis is applied to all media files, then detection reliability improves, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the steganalysis process into distinct modular components: media file interceptors, classification modules, steganalysis operators, and remediation systems. Each module handles specific aspects of detection, allowing the system to apply comprehensive analysis only where needed while keeping overall system complexity manageable through modular architecture and selective processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different levels of analysis intensity to different media files based on risk assessment. High-risk files undergo comprehensive steganalysis with multiple operators, while low-risk files receive minimal or no analysis. This localized quality approach maintains high detection reliability for critical cases while reducing overall system complexity and processing overhead.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If steganographically hidden content is detected and disrupted, then network security is improved, but the carrier media file may be damaged or corrupted

Engineering Contradiction:
Improvenetwork securityVSAvoidcarrier file integrity
Core Design Contradiction:
Object-affected harmful factorsVSStability of the object's composition

Solution Approach 1:

The patent extracts and removes only the steganographically hidden malicious content from the carrier media file while leaving the original media content intact. The disruption process targets specifically the embedded malware or confidential information, separating it from the legitimate carrier file, thus improving network security by eliminating the threat while preserving the stability and usability of the original media file.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3721365B1Methods, systems and apparatus to mitigate steganography-based malware attacks
Publication Date: 2022.04.20 MCAFEE LLC
  • EP3721365B1 patent drawingFigure 1
  • EP3721365B1 patent drawingFigure 2
  • EP3721365B1 patent drawingFigure 3A~5

AI summary

Methods, apparatus, systems and articles of manufacture to detect steganographically hidden content in a media file are disclosed. An example system includes a media classifier to determine type of a media file, and a detector to apply a detection technique to the media file. The detector selects the detection technique from a plurality of steganographically-based detection techniques based on the media file type. The system also includes a remediator to apply a remediation technique to the media file based on whether the detector detects steganographically hidden content in the media file.