Virtual I/O Identifier Misrepresentation for Malware Evasion Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware detection systems are unable to effectively counter malware evasion techniques, as virtualizing newly released I/O devices is complex and costly, allowing malware to recognize and evade detection by identifying virtualized environment components.

Innovation Solution

The system employs virtual machines with modified software components and identifiers to misrepresent virtual I/O components, making it difficult for malware to determine if it is in a virtual environment, thereby preventing evasion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional malware detection systems virtualize I/O devices to detect malware, then malware detection capability is improved, but device complexity and implementation cost increase significantly

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidvirtualization implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of physical I/O devices (virtual I/O devices) that replicate the functionality and identifiers of real devices. These virtual copies are presented to malware within the sandbox environment, allowing malware to interact with device identifiers without requiring actual physical device virtualization. This copying approach maintains detection reliability while reducing the complexity of implementing and maintaining virtualized hardware devices.

Inventive Principle:
Principle #26Copying

2Ease of operation

If malware detection systems use standard virtualized I/O device identifiers, then system operation is simplified, but malware can easily recognize and evade detection by identifying virtual environment components

Engineering Contradiction:
Improvesystem operation simplicityVSAvoiddetection effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent dynamically changes the identifiers assigned to virtual I/O devices presented within the sandbox. Instead of using fixed, standard virtual device identifiers, the system modifies device identifiers (such as PCI device IDs, vendor IDs, or other hardware identification parameters) to appear as legitimate physical devices. This parameter transformation prevents malware from recognizing the virtual environment while maintaining ease of system operation through software-based identifier management.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If malware detection systems virtualize newly released I/O devices, then detection coverage is improved, but implementation time and cost increase substantially

Engineering Contradiction:
Improvedetection coverageVSAvoidvirtualization implementation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent creates virtual representations of newly released I/O devices through software-based identifier assignment rather than requiring actual hardware virtualization. When a new physical I/O device is released, the system can quickly assign appropriate virtual identifiers to represent it in the sandbox environment without undergoing complex virtualization implementation processes. This copying approach enables rapid adaptation to new device types while minimizing implementation time and resource requirements.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10747872B1System and method for preventing malware evasion
Publication Date: 2020.08.18 MAGENTA SECURITY HOLDINGS LLC
  • US10747872B1 patent drawing
  • US10747872B1 patent drawing
  • US10747872B1 patent drawing

AI summary

A computerized method that assists in preventing malware from evading detection through analysis of the virtual hardware components operating within a malware detection system is described. First, a virtual machine (VM) is provisioned in accordance with a guest image, which includes a guest operating system and one or more virtual hardware component. The virtual hardware component including an identifier, and the guest operating system includes a software driver that controls access to the virtual hardware component and features the identifier of the virtual hardware component. Responsive to processing an object within the VM and issuance of a request for an identifier of a hardware component, the identifier of the first virtualized hardware component (virtualization of the hardware component) is received. The first identifier of the first virtual hardware component being an identifier substituted for a prior identifier of the first virtual hardware component before creation of the guest image.