Virtual Machine Clustering for Malware Detection and Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware detection systems face challenges in proactively controlling the spread of malware across electronic devices, as malware-spreading agents often evade detection by policy engines and web filtering applications, and behavior-based monitoring approaches are complex and prone to errors.

Innovation Solution

A method involving the generation of virtual machines in a server, clustering them based on profile information from terminals, and sharing this information to detect and alert other terminals within the same cluster when malware is identified, thereby reducing communication between potentially infected devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional policy engines and web filtering applications are used to block malware sources, then known malware sources can be controlled, but malware-spreading agents can evade detection and spread malware

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoidmalware evasion capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a feedback mechanism where terminals share malware detection information with other terminals in the same cluster. When a terminal detects malware, it notifies the server, which then alerts other terminals in the cluster, creating a continuous feedback loop that improves collective detection reliability and prevents evasion by adapting to new malware variants

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by pre-clustering terminals based on their profiles before malware infection occurs. This pre-grouping enables rapid response when malware is detected, as the system can immediately notify the appropriate cluster members without needing to analyze network traffic patterns in real-time, thus preventing malware spread before it can propagate widely

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If behavior-based monitoring approaches are used to detect malware, then malware can be detected through profile analysis, but the approach becomes complicated and prone to errors

Engineering Contradiction:
Improvemalware detection precisionVSAvoidprofile construction complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the large-scale malware detection problem into smaller, manageable clusters of terminals. Instead of analyzing all terminals globally, the system divides them into profile-based clusters and performs monitoring within each cluster, reducing complexity while maintaining detection precision through localized analysis

Inventive Principle:
Principle #1Segmentation

3Reliability

If basic detection and blocking mechanisms are used, then malware spread can be controlled, but proactive control of malware spreading across electronic devices is insufficient

Engineering Contradiction:
Improvemalware spread controlVSAvoidmalware response efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple functions into a unified system: profile-based clustering, virtual machine generation, malware detection, and inter-terminal notification are combined into an integrated architecture. This merging enables proactive control by coordinating these functions to work together, improving both reliability and productivity in malware response

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9361461B2Method and apparatus for detecting malware and recording medium thereof
Publication Date: 2016.06.07 SAMSUNG ELECTRONICS CO LTD
  • US9361461B2 patent drawing
  • US9361461B2 patent drawing
  • US9361461B2 patent drawing

AI summary

A method of detecting malware in a terminal, the method including: generating a plurality of virtual machines in the server, the plurality of virtual machines respectively corresponding to a plurality of terminals; clustering the plurality of generated virtual machines into groups based on respective profile information of each terminal of the plurality of terminals; and in response to the malware being detected in a first terminal among the plurality of terminals, providing information with respect to the detection of the malware to a second terminal among the plurality of terminals corresponding to a second virtual machine, via the second virtual machine among the plurality of virtual machines, the second virtual machine being clustered into the same group as a first virtual machine.