Virtualized Storage for Dynamic Malware Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of mobile devices for work-related activities has led to a rise in malware targeting these devices, necessitating improved techniques for identifying and mitigating malicious software, especially since traditional computer security measures are less effective on mobile platforms.

Innovation Solution

A system comprising a data appliance and a security platform that performs dynamic analysis of applications, using both static and dynamic analysis techniques to identify malicious behavior, and integrates with firewalls to enforce policies and block malicious traffic, while also utilizing virtualized environments to simulate user interactions and monitor application behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional computer security measures are used on mobile devices, then implementation simplicity is maintained, but malware detection effectiveness deteriorates

Engineering Contradiction:
Improvemalware detection effectivenessVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the mobile device environment (virtual machine) to execute and analyze the application. This copying approach allows comprehensive security analysis without modifying the actual device, resolving the contradiction by enabling complex analysis in an isolated virtual environment while keeping the real device simple and secure.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a security platform as an intermediary between the mobile device and the malware analysis process. This intermediary handles the complex analysis tasks remotely, allowing the mobile device to remain simple while achieving high detection effectiveness through the intermediary's sophisticated analysis capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If dynamic analysis with virtualized environments is implemented, then malware detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security analysis system into distinct functional modules: a virtual machine component for execution, a monitoring component for behavior tracking, and an analysis component for evaluating collected data. This segmentation enables high detection accuracy through comprehensive analysis while managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a virtual copy of the mobile operating system and application environment to perform dynamic analysis. This copying enables precise measurement of malware behavior in a controlled setting without complicating the actual mobile device, as all complex operations occur in the virtual replica.

Inventive Principle:
Principle #26Copying

3Reliability

If comprehensive static and dynamic analysis techniques are used, then false positives are reduced, but processing time increases

Engineering Contradiction:
Improvefalse positive rateVSAvoidanalysis processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs static analysis (examining code without execution) before dynamic analysis. This preliminary action identifies obvious malware characteristics early, allowing the system to quickly flag suspicious applications without requiring time-consuming dynamic execution for every app, thus reducing false positives while managing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring during the dynamic analysis phase, collecting behavioral data throughout the application's execution rather than relying on discrete snapshots. This continuous observation improves detection accuracy by capturing subtle malicious behaviors while the automated virtual environment maintains efficient processing speeds.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11604878B2Dynamic analysis techniques for applications
Publication Date: 2023.03.14 PALO ALTO NETWORKS INC
  • US11604878B2 patent drawing
  • US11604878B2 patent drawing
  • US11604878B2 patent drawing

AI summary

A virtualized storage for use in performing dynamic analysis on a sample is configured, at least in part by copying the sample to the virtualized storage. A virtual machine emulator is launched using a snapshot of a virtualized platform. The virtualized platform is previously configured to use the virtualized storage, and the snapshot is configured to use a placeholder file to occupy space for later use when installing the sample. A location of the copied sample in an image corresponding to the virtualized storage is determined. The copied sample is installed and dynamic analysis is performed on the sample.