Virtual Machine Malware Detection via Application-Specific Event Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware detection systems using virtual machines often misclassify ingress content as benign or malicious due to a lack of contextual understanding, leading to false negatives and false positives, which can impact system performance and dilute true positive responses.

Innovation Solution

A malware content detection system that intercepts and analyzes suspect objects using virtual machines, employing multiple stages of analysis including static and dynamic analysis, with monitors capturing process operations and parameters to infer application-specific behaviors, and utilizing whitelists, blacklists, state machines, and machine learning rules to generate confidence scores for accurate classification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional virtual machine-based monitoring is used to detect malware, then the system can identify unexpected operations, but it produces false positives and false negatives due to lack of contextual understanding

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidclassification reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent changes the parameters of monitoring by transitioning from conventional operation monitoring to application-specific event monitoring. It introduces a new parameter set including application-specific event types, parameters, and states that capture contextual information about what the application is supposed to be doing, enabling more accurate distinction between legitimate and malicious operations

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary layer between the application and the monitoring system. This intermediary captures and translates application operations into standardized application-specific events with contextual parameters, allowing the monitoring system to understand the intended behavior and differentiate it from malicious behavior without requiring deep application-specific knowledge

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If operation monitoring is performed without contextual knowledge, then the system can detect anomalous operations, but it leads to incorrect classification of ingress content

Engineering Contradiction:
Improveoperation monitoring capabilityVSAvoidcontent classification accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The patent segments the monitoring approach into distinct layers: application-specific event definition, event capture, parameter extraction, and analysis. Each layer handles a specific aspect of contextual understanding, allowing the system to maintain operation monitoring capabilities while adding contextual precision through structured event modeling

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary action by pre-defining application-specific events, parameters, and expected states before monitoring begins. This preparation includes establishing what normal operations look like for each application type, enabling the system to immediately contextualize observed operations and improve classification accuracy

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10534906B1Detection efficacy of virtual machine-based analysis with application specific events
Publication Date: 2020.01.14 MAGENTA SECURITY HOLDINGS LLC
  • US10534906B1 patent drawing
  • US10534906B1 patent drawing
  • US10534906B1 patent drawing

AI summary

A computerized system and method is described for classifying objects as malicious by processing the objects in a virtual environment and monitoring behaviors during processing by one or more monitors, where the monitoring is conducted in an electronic device that is different than the electronic device within which an analysis of attributes of the objects is conducted beforehand. The monitors may monitor and record selected sets of process operations and capture associated process parameters, which describe the context in which the process operations were performed. By recording the context of process operations, the system and method described herein improves the intelligence of classifications and consequently reduces the likelihood of incorrectly identifying objects as malware or vice versa.