Virtual I/O Identifier Misrepresentation for Malware Evasion Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional malware detection systems are unable to effectively counter malware evasion techniques, as virtualizing newly released I/O devices is complex and costly, allowing malware to recognize and evade detection by identifying virtualized environment components.
Innovation Solution
The system employs virtual machines with modified software components and identifiers to misrepresent virtual I/O components, making it difficult for malware to determine if it is in a virtual environment, thereby preventing evasion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional malware detection systems virtualize I/O devices to detect malware, then malware detection capability is improved, but device complexity and implementation cost increase significantly
Solution Approach 1:
The patent creates virtual copies of physical I/O devices (virtual I/O devices) that replicate the functionality and identifiers of real devices. These virtual copies are presented to malware within the sandbox environment, allowing malware to interact with device identifiers without requiring actual physical device virtualization. This copying approach maintains detection reliability while reducing the complexity of implementing and maintaining virtualized hardware devices.
2Ease of operation
If malware detection systems use standard virtualized I/O device identifiers, then system operation is simplified, but malware can easily recognize and evade detection by identifying virtual environment components
Solution Approach 1:
The patent dynamically changes the identifiers assigned to virtual I/O devices presented within the sandbox. Instead of using fixed, standard virtual device identifiers, the system modifies device identifiers (such as PCI device IDs, vendor IDs, or other hardware identification parameters) to appear as legitimate physical devices. This parameter transformation prevents malware from recognizing the virtual environment while maintaining ease of system operation through software-based identifier management.
3Adaptability or versatility
If malware detection systems virtualize newly released I/O devices, then detection coverage is improved, but implementation time and cost increase substantially
Solution Approach 1:
The patent creates virtual representations of newly released I/O devices through software-based identifier assignment rather than requiring actual hardware virtualization. When a new physical I/O device is released, the system can quickly assign appropriate virtual identifiers to represent it in the sandbox environment without undergoing complex virtualization implementation processes. This copying approach enables rapid adaptation to new device types while minimizing implementation time and resource requirements.
Data Source
AI summary
A computerized method that assists in preventing malware from evading detection through analysis of the virtual hardware components operating within a malware detection system is described. First, a virtual machine (VM) is provisioned in accordance with a guest image, which includes a guest operating system and one or more virtual hardware component. The virtual hardware component including an identifier, and the guest operating system includes a software driver that controls access to the virtual hardware component and features the identifier of the virtual hardware component. Responsive to processing an object within the VM and issuance of a request for an identifier of a hardware component, the identifier of the first virtualized hardware component (virtualization of the hardware component) is received. The first identifier of the first virtual hardware component being an identifier substituted for a prior identifier of the first virtual hardware component before creation of the guest image.


