USB Malicious Code Analysis Device Bypassing Environment Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malicious code analysis methods struggle to accurately analyze the real-time activity of environment-aware malicious code, especially when it recognizes virtual environments and uses encryption, as they often rely on post-execution hard disk forensics and network packet analysis, which fail to observe activity during execution and handle encrypted data effectively.

Innovation Solution

A malicious code analysis method and device that connect via a USB cable, allowing multi-booting on the target terminal with multiple OS image files, providing user input to simulate genuine user interaction, and analyzing modified data to detect malicious code activity in real-time, across various devices and OS environments, including PCs and mobile devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual environment is used for malicious code analysis, then the analysis environment can be easily restored to clean state, but malicious code can recognize the virtual environment and perform different operations, making analysis difficult

Engineering Contradiction:
Improveenvironment restoration capabilityVSAvoidmalicious code activity detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system divides the analysis into two independent parts: the malicious code execution environment (target terminal) and the observation environment (analysis device). By connecting via USB cable, the analysis device can observe the target terminal's memory and storage without the malicious code being able to detect the virtualization layer, thus preventing environment recognition while maintaining analysis capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The USB cable connection acts as an intermediary between the analysis device and target terminal. This physical connection allows the analysis device to directly access and monitor the target terminal's memory and storage contents without being detected by the malicious code, effectively bypassing the virtual environment detection mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If hard disk forensics is used to extract malicious code activity, then the analysis can be performed in actual environment, but it is impossible to observe the activity of malicious code in detail while being executed

Engineering Contradiction:
Improveanalysis environment accessibilityVSAvoidreal-time activity observation capability
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and capturing memory and storage data during malicious code execution. The analysis device records the target terminal's state changes in real-time, so when analysis is needed, the data is already captured and can be examined without requiring post-execution forensic analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback loop where the analysis device continuously monitors the target terminal's memory and storage, detects changes caused by malicious code execution, and provides real-time analysis feedback. This allows observers to see malicious code activity as it happens, rather than only after execution completes.

Inventive Principle:
Principle #23Feedback

3Loss of information

If network packet analysis is used to observe network activity, then external network access can be analyzed, but analysis is impossible when malicious code uses encrypted data

Engineering Contradiction:
Improvenetwork communication monitoring capabilityVSAvoidencrypted data analysis capability
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The USB cable connection serves as an intermediary that allows direct access to the target terminal's memory and storage. This physical access enables the analysis device to capture encrypted data in its raw form before it is processed or transmitted, allowing analysis of the encryption mechanisms and data content without being blocked by the encryption itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If sandbox environment is used for analysis, then security is improved by isolating malicious code, but environment-aware malicious code can detect the sandbox and avoid execution

Engineering Contradiction:
Improvesecurity isolation capabilityVSAvoidmalicious code execution reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system segments the analysis setup into a isolated target terminal connected via USB to the analysis device. The target terminal runs the malicious code in a controlled environment while the analysis device observes from outside. This physical segmentation prevents the malicious code from detecting the broader sandbox environment while maintaining security isolation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10366226B2Malicious code analysis device and method based on external device connected via USB cable
Publication Date: 2019.07.30 ELECTRONICS & TELECOMM RES INST
  • US10366226B2 patent drawing
  • US10366226B2 patent drawing
  • US10366226B2 patent drawing

AI summary

A malicious code analysis device and method used on an external device connected via a USB cable. The malicious code analysis method includes connecting a malicious code analysis device to an analysis target terminal, on which malicious code is to be executed, from outside the analysis target terminal via a USB cable, multi-booting the analysis target terminal based on multiple Operating System (OS) image files stored in the malicious code analysis device; providing user input to the analysis target terminal so that malicious code is incapable of recognizing that a current environment is an analysis environment, and analyzing, by the malicious code analysis device, the malicious code in consideration of both data modified by the malicious code, among pieces of data corresponding to the multiple OS image files, and the user input.