USB Malicious Code Analysis Device Bypassing Environment Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malicious code analysis methods struggle to accurately analyze the real-time activity of environment-aware malicious code, especially when it recognizes virtual environments and uses encryption, as they often rely on post-execution hard disk forensics and network packet analysis, which fail to observe activity during execution and handle encrypted data effectively.
Innovation Solution
A malicious code analysis method and device that connect via a USB cable, allowing multi-booting on the target terminal with multiple OS image files, providing user input to simulate genuine user interaction, and analyzing modified data to detect malicious code activity in real-time, across various devices and OS environments, including PCs and mobile devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual environment is used for malicious code analysis, then the analysis environment can be easily restored to clean state, but malicious code can recognize the virtual environment and perform different operations, making analysis difficult
Solution Approach 1:
The system divides the analysis into two independent parts: the malicious code execution environment (target terminal) and the observation environment (analysis device). By connecting via USB cable, the analysis device can observe the target terminal's memory and storage without the malicious code being able to detect the virtualization layer, thus preventing environment recognition while maintaining analysis capability.
Solution Approach 2:
The USB cable connection acts as an intermediary between the analysis device and target terminal. This physical connection allows the analysis device to directly access and monitor the target terminal's memory and storage contents without being detected by the malicious code, effectively bypassing the virtual environment detection mechanism.
2Ease of operation
If hard disk forensics is used to extract malicious code activity, then the analysis can be performed in actual environment, but it is impossible to observe the activity of malicious code in detail while being executed
Solution Approach 1:
The system performs preliminary actions by continuously monitoring and capturing memory and storage data during malicious code execution. The analysis device records the target terminal's state changes in real-time, so when analysis is needed, the data is already captured and can be examined without requiring post-execution forensic analysis.
Solution Approach 2:
The system establishes a feedback loop where the analysis device continuously monitors the target terminal's memory and storage, detects changes caused by malicious code execution, and provides real-time analysis feedback. This allows observers to see malicious code activity as it happens, rather than only after execution completes.
3Loss of information
If network packet analysis is used to observe network activity, then external network access can be analyzed, but analysis is impossible when malicious code uses encrypted data
Solution Approach 1:
The USB cable connection serves as an intermediary that allows direct access to the target terminal's memory and storage. This physical access enables the analysis device to capture encrypted data in its raw form before it is processed or transmitted, allowing analysis of the encryption mechanisms and data content without being blocked by the encryption itself.
4Object-affected harmful factors
If sandbox environment is used for analysis, then security is improved by isolating malicious code, but environment-aware malicious code can detect the sandbox and avoid execution
Solution Approach 1:
The system segments the analysis setup into a isolated target terminal connected via USB to the analysis device. The target terminal runs the malicious code in a controlled environment while the analysis device observes from outside. This physical segmentation prevents the malicious code from detecting the broader sandbox environment while maintaining security isolation.
Data Source
AI summary
A malicious code analysis device and method used on an external device connected via a USB cable. The malicious code analysis method includes connecting a malicious code analysis device to an analysis target terminal, on which malicious code is to be executed, from outside the analysis target terminal via a USB cable, multi-booting the analysis target terminal based on multiple Operating System (OS) image files stored in the malicious code analysis device; providing user input to the analysis target terminal so that malicious code is incapable of recognizing that a current environment is an analysis environment, and analyzing, by the malicious code analysis device, the malicious code in consideration of both data modified by the malicious code, among pieces of data corresponding to the multiple OS image files, and the user input.


