Virtual Machine Instrumentation for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware detection systems in virtual environments are inefficient as they use a standard replay process without considering specific exploits or malware analysis results, leading to delayed detection and potential propagation of malware.

Innovation Solution

A malware content detection system that dynamically adjusts virtual machine instrumentation based on malware analysis results during replay operations, allowing for targeted and efficient exploit detection by altering VM processes transparently to the guest system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a standard replay process is used without considering specific exploits or malware analysis results, then the system maintains simplicity and ease of operation, but detection accuracy and efficiency deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic adjustment of VM instrumentation based on malware analysis results. The system transitions from static, generic replay processes to dynamic, adaptive processes that modify instrumentation in real-time based on detected threats, thereby improving detection accuracy without requiring complete system redesign

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where malware analysis results from initial replay operations inform subsequent instrumentation adjustments. The analysis results feed back into the replay process, enabling the system to adapt and improve detection accuracy based on actual malware behavior observations

Inventive Principle:
Principle #23Feedback

2Productivity

If generic VM instrumentation continues to run without intelligence on making run-time more efficient, then the system maintains operational simplicity, but detection efficiency and speed deteriorate

Engineering Contradiction:
Improvedetection efficiencyVSAvoidoperational simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system performs preliminary malware analysis during initial replay operations to gather intelligence about the malware behavior. This preliminary action enables subsequent optimization of the replay process by configuring instrumentation specifically tailored to the detected malware characteristics, thereby improving detection efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically changes instrumentation parameters based on malware analysis results. The system adjusts replay parameters, instrumentation levels, and detection thresholds in real-time based on observed malware behavior, enabling more efficient detection without requiring manual reconfiguration

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the same replay process is used without considering malware analysis results, then the system maintains consistency and stability, but detection precision and timeliness deteriorate

Engineering Contradiction:
Improvedetection precisionVSAvoidprocess stability
Core Design Contradiction:
Measurement precisionVSStability of the object's composition

Solution Approach 1:

The system introduces controlled dynamics into the replay process by adjusting instrumentation based on malware analysis results. This dynamic adaptation allows the system to maintain stability in its core functionality while improving detection precision through targeted instrumentation changes responsive to actual malware behavior

Inventive Principle:
Principle #15Dynamics

4Reliability

If antivirus scanning is used to detect malware, then the system maintains simplicity in implementation, but detection effectiveness deteriorates due to delayed detection and inability to detect polymorphic malware

Engineering Contradiction:
Improvedetection effectivenessVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional antivirus scanning mechanisms with a virtualized replay system that executes malware in a controlled virtual environment. This substitution enables behavioral analysis and detection of polymorphic malware that signature-based scanning cannot detect, significantly improving detection effectiveness despite increased system complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11075945B2System, apparatus and method for reconfiguring virtual machines
Publication Date: 2021.07.27 MANDIANT LLC
  • US11075945B2 patent drawing
  • US11075945B2 patent drawing
  • US11075945B2 patent drawing

AI summary

According to one embodiment, a computerized method operates by configuring a virtual machine operating within an electronic device with a first instrumentation for processing of a suspicious object. In response to detecting a type of event during processing of the suspicious object within the virtual machine, the virtual machine is automatically reconfigured with a second instrumentation that is different from the first instrumentation in efforts to achieve reduced configuration time and/or increased effectiveness in exploit detection.