Virtual Machine Malware Analysis System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Analyzing the effects of malware execution is labor-intensive and often limited to specific operating environments, making it cumbersome for collective evaluation by multiple analysts.
Innovation Solution
A system and method that utilize a virtual machine to execute software components in a target operating system, monitoring kernel and application level events, and recommending analysis procedures based on digital identifier comparisons in a database.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If malware analysis is performed manually by analysts, then detailed security vulnerability discovery is achieved, but the process becomes labor-intensive and time-consuming
Solution Approach 1:
A virtual machine environment is introduced as an intermediary between the malware and the analysis system. The virtual machine executes the malware and captures detailed system calls, registry changes, file operations, and network communications, providing structured data that maintains analysis precision while reducing manual effort.
Solution Approach 2:
Instead of directly analyzing malware on physical systems, the patent creates virtual copies of operating systems and system environments. These virtual copies allow multiple analysts to simultaneously evaluate malware effects without risking actual systems, significantly reducing analysis time while maintaining detailed observation capabilities.
2Ease of operation
If analysis is limited to a particular operating environment, then the analysis process is simplified, but the environment may not be representative of the target operating environment
Solution Approach 1:
The virtual machine platform provides a universal environment that can be configured to represent multiple target operating systems. The same analysis system can evaluate malware against different virtualized OS environments (Windows, Linux, macOS), ensuring that the analysis is both operationally simple and reliably representative of various target environments.
3Measurement precision
If collective evaluation by a team of analysts is undertaken, then comprehensive malware assessment is achieved, but the process becomes cumbersome
Solution Approach 1:
The patent divides the malware analysis process into distinct virtualized environments that can be independently configured and executed. Each analyst can work with segmented virtual machine instances, and the system automatically aggregates results from multiple evaluations, reducing process complexity while maintaining comprehensive assessment capabilities.
Data Source
AI summary
A particular method includes receiving, at a device, a request to analyze a software component. The request indicates a target operating system. The method also includes generating a virtual machine at a computing device. The virtual machine implements the target operating system. The method further includes executing the software component in the target operating system on the virtual machine and generating data indicating effects of executing the software component on the virtual machine.


